Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 Maven

Keycloak's admin API allows low privilege users to use administrative functions

GHSA-2cww-fgmg-4jqc · CVE-2024-3656

Published · Modified

Description

Users with low privileges (just plain users in the realm) are able to utilize administrative functionalities within Keycloak admin interface. This issue presents a significant security risk as it allows unauthorized users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.

Acknowledgements:
Special thanks to Maurizio Agazzini for reporting this issue and helping us improve our project.

Ready to move

Start Securing

Free, no credit card | First findings in minutes