PT-2024-4295 · Red Hat · Keycloak

Maurizio Agazzini

·

Published

2024-06-11

·

Updated

2024-12-23

·

CVE-2024-3656

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak versions prior to 24.0.5
Description A flaw was found in Keycloak, where certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This issue presents a significant security risk as it allows unauthorized users to perform actions reserved for administrators, potentially leading to data breaches or system compromise. The vulnerability is actively exploited in the wild. Over 39,000 results are found on ZoomEye, and over 763,000 services are found on the affected platform yearly.
Recommendations For versions prior to 24.0.5, upgrade to version 24.0.5 or newer to secure your systems. As a temporary workaround, consider restricting access to the administrative REST API endpoints until a patch is available. Avoid using the administrative functionalities in the Keycloak admin interface with low-privilege users until the issue is resolved.

Exploit

Fix

Information Disclosure

Improper Access Control

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-04782
CVE-2024-3656
GHSA-2CWW-FGMG-4JQC

Affected Products

Keycloak