First published: Wed Apr 10 2024(Updated: )
Users with low privileges (just plain users in the realm) are able to utilize administrative functionalities within Keycloak admin interface. This issue presents a significant security risk as it allows unauthorized users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Build of Keycloak |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2274403 is high due to the significant security risk it poses by allowing unauthorized access to administrative functionalities.
To fix REDHAT-BUG-2274403, ensure that proper access controls are enforced in the Keycloak admin interface to restrict administrative functionalities to authorized users only.
Users with low privileges in the Keycloak environment are affected by REDHAT-BUG-2274403 as they can exploit administrative functionalities.
The impact of REDHAT-BUG-2274403 includes unauthorized users being able to perform actions reserved for administrators, potentially compromising sensitive data.
REDHAT-BUG-2274403 was reported as a bug in the Red Hat Keycloak, highlighting a critical security issue.