Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 Maven

Keycloak has lack of validation of access token on client registrations endpoint

GHSA-v436-q368-hvgg · CVE-2023-0091

Published · Modified

Description

When a service account with the create-client or manage-clients role can use the client-registration endpoints to create/manage clients with an access token.

If the access token is leaked, there is an option to revoke the specific token. However, the check is not performed in client-registration endpoints.

Ready to move

Start Securing

Free, no credit card | First findings in minutes