REDHAT-BUG-2292200: Low severity Keycloak Keycloak vulnerability
The LDAP testing endpoint allows to change the Connection URL independently of and without having to re-enter the currently configured LDAP bind credentials. An attacker with admin access (permission manage-realm) can change the LDAP host URL ("Connection URL") to a machine they control. The Keycloak server will connect to the attacker's host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console/compromised a user with sufficient privileges can leak domain credentials and can now attack the domain.
This requires: Access to the REST endpoint and the admin user needed with manage-realm permission (full access to LDAP configuration and all identity providers).
Version affected: <= 24.0.5
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Keycloakto a version that resolves this vulnerability.Fixed in 24.0.5 - Compensating control
Restrict access to the LDAP testing REST endpoint so attackers cannot change the LDAP “Connection URL” independently of the currently configured LDAP bind credentials.
- Compensating control
Restrict access to the admin console/REST APIs to only trusted administrators with the required “manage-realm” permission, since this permission enables full access to LDAP configuration (including “Connection URL”).
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2292200?
The severity of REDHAT-BUG-2292200 is considered critical due to the risk of unauthorized access to LDAP configurations.
How do I fix REDHAT-BUG-2292200?
To fix REDHAT-BUG-2292200, update to the latest version of Keycloak that includes the security patches addressing this vulnerability.
Who is affected by REDHAT-BUG-2292200?
REDHAT-BUG-2292200 affects all installations of Keycloak versions up to and including 24.0.5.
What is the potential impact of REDHAT-BUG-2292200?
The potential impact of REDHAT-BUG-2292200 includes the ability for an attacker to redirect LDAP connections, potentially leading to data exposure.
Is there a workaround for REDHAT-BUG-2292200?
Currently, the recommended action for REDHAT-BUG-2292200 is to apply the security updates rather than relying on a workaround.