MEDIUM 6.5 Maven

Keycloak has lack of validation of access token on client registrations endpoint

GHSA-v436-q368-hvgg · CVE-2023-0091

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

When a service account with the create-client or manage-clients role can use the client-registration endpoints to create/manage clients with an access token.

If the access token is leaked, there is an option to revoke the specific token. However, the check is not performed in client-registration endpoints.

Ready to move

Start Securing

Free, no credit card | First findings in minutes