HIGH 8.1 Maven
Keycloak's admin API allows low privilege users to use administrative functions
GHSA-2cww-fgmg-4jqc · CVE-2024-3656
Published · Modified
Description
Users with low privileges (just plain users in the realm) are able to utilize administrative functionalities within Keycloak admin interface. This issue presents a significant security risk as it allows unauthorized users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.
Acknowledgements:
Special thanks to Maurizio Agazzini for reporting this issue and helping us improve our project.
References
- WEB https://github.com/keycloak/keycloak/security/advisories/GHSA-2cww-fgmg-4jqc
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-3656
- WEB https://github.com/keycloak/keycloak/commit/d9f0c84b797525eac55914db5f81a8133ef5f9b1
- WEB https://access.redhat.com/errata/RHSA-2024:3572
- WEB https://access.redhat.com/errata/RHSA-2024:3575
- WEB https://access.redhat.com/security/cve/CVE-2024-3656
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2274403
- ADVISORY https://github.com/advisories/GHSA-2cww-fgmg-4jqc
- WEB https://github.com/hnsecurity/vulns/blob/main/HNS-2024-08-Keycloak.md
- PACKAGE https://github.com/keycloak/keycloak
- WEB https://news.ycombinator.com/item?id=42136000
- WEB https://security.humanativaspa.it/an-analysis-of-the-keycloak-authentication-system
Ready to move
Start Securing
Free, no credit card | First findings in minutes