First published: Wed Apr 30 2025(Updated: )
# Description A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.keycloak:keycloak-services | <26.2.2 | 26.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
GHSA-5jfq-x6xp-7rw2 is classified as a moderate severity vulnerability.
To fix GHSA-5jfq-x6xp-7rw2, upgrade to Keycloak version 26.2.2 or later.
GHSA-5jfq-x6xp-7rw2 describes a flaw that may allow users to circumvent required actions, such as two-factor authentication.
GHSA-5jfq-x6xp-7rw2 affects Keycloak versions prior to 26.2.2.
GHSA-5jfq-x6xp-7rw2 is associated with the org.keycloak.authorization package.