MEDIUM 6.5 Maven
Keycloak has lack of validation of access token on client registrations endpoint
GHSA-v436-q368-hvgg · CVE-2023-0091
Published · Modified
Description
When a service account with the create-client or manage-clients role can use the client-registration endpoints to create/manage clients with an access token.
If the access token is leaked, there is an option to revoke the specific token. However, the check is not performed in client-registration endpoints.
Ready to move
Start Securing
Free, no credit card | First findings in minutes