VDB
Sign up
LOW3.1

GHSA-r8jr-wg88-fq5c

Keycloak vulnerable to authorization bypass via the Admin API

Details

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@keycloak/keycloak-admin-client
Introduced in: 0

No fixed version published yet for @keycloak/keycloak-admin-client (npm). Pin to a known-safe version or switch to an alternative.

Maven/org.keycloak:keycloak-js-admin-client
Introduced in: 0

No fixed version published yet for org.keycloak:keycloak-js-admin-client (maven). Pin to a known-safe version or switch to an alternative.

References