VDB
Sign up
HIGH8.1

GHSA-f2hx-5fx3-hmcv

Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants

Quick fix

GHSA-f2hx-5fx3-hmcv — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-services

Details

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 26.5.7
Fix# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-services

References