CVE-2019-14832: High severity redhat Keycloak vulnerability
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.
Other sources
A flaw was found in the Keycloak REST API before version 8.0.0, implemented in Keycloak before 7.0.1 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.
A flaw was found in the Keycloak REST API where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.
Keycloak permits some access to a user in one realm from a user logged into another. An attacker could use this to access restricted information, or carry out further attacks.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.keycloak:keycloak-model-jpato a version that resolves this vulnerability.Fixed in 7.0.1 - Upgrade
Upgrade
maven/org.keycloak:keycloak-model-infinispanto a version that resolves this vulnerability.Fixed in 7.0.1 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:4.8.13-1.Final_redhat_00001.1.el6 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:4.8.13-1.Final_redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-libunix-dbus-javato a version that resolves this vulnerability.Fixed in 0:0.8.0-2.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:4.8.13-1.Final_redhat_00001.1.el8 - Upgrade
Upgrade
redhat/keycloakto a version that resolves this vulnerability.Fixed in 7.0.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-14832?
CVE-2019-14832 is a vulnerability in the Keycloak REST API that allows unauthorized access to user information.
What is the severity of CVE-2019-14832?
CVE-2019-14832 has a severity rating of 7.5 (high).
How does CVE-2019-14832 impact Keycloak before version 7.0.1?
CVE-2019-14832 allows an authenticated attacker with knowledge of a user id to access unauthorized information or carry out unauthorized actions.
How do I fix the CVE-2019-14832 vulnerability?
To fix the CVE-2019-14832 vulnerability, update Keycloak to version 7.0.1 or later.
Are there any additional references for CVE-2019-14832?
Yes, you can refer to the following links for more information on CVE-2019-14832: [Reference 1](https://access.redhat.com/errata/RHSA-2019:3044), [Reference 2](https://access.redhat.com/errata/RHSA-2019:3045), [Reference 3](https://access.redhat.com/errata/RHSA-2019:3046).