REDHAT-BUG-2292200: Low severity Keycloak Keycloak vulnerability

Published Jun 13, 2024
·
Updated

The LDAP testing endpoint allows to change the Connection URL independently of and without having to re-enter the currently configured LDAP bind credentials. An attacker with admin access (permission manage-realm) can change the LDAP host URL ("Connection URL") to a machine they control. The Keycloak server will connect to the attacker's host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console/compromised a user with sufficient privileges can leak domain credentials and can now attack the domain.

This requires: Access to the REST endpoint and the admin user needed with manage-realm permission (full access to LDAP configuration and all identity providers).

Version affected: <= 24.0.5

Affected Software

1 affected component
Keycloak Keycloak<=24.0.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Keycloak to a version that resolves this vulnerability.

    Fixed in 24.0.5
  2. Compensating control

    Restrict access to the LDAP testing REST endpoint so attackers cannot change the LDAP “Connection URL” independently of the currently configured LDAP bind credentials.

  3. Compensating control

    Restrict access to the admin console/REST APIs to only trusted administrators with the required “manage-realm” permission, since this permission enables full access to LDAP configuration (including “Connection URL”).

Event History

Jun 13, 2024
Data Sourced
via Red Hat·12:37 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2292200?

The severity of REDHAT-BUG-2292200 is considered critical due to the risk of unauthorized access to LDAP configurations.

2

How do I fix REDHAT-BUG-2292200?

To fix REDHAT-BUG-2292200, update to the latest version of Keycloak that includes the security patches addressing this vulnerability.

3

Who is affected by REDHAT-BUG-2292200?

REDHAT-BUG-2292200 affects all installations of Keycloak versions up to and including 24.0.5.

4

What is the potential impact of REDHAT-BUG-2292200?

The potential impact of REDHAT-BUG-2292200 includes the ability for an attacker to redirect LDAP connections, potentially leading to data exposure.

5

Is there a workaround for REDHAT-BUG-2292200?

Currently, the recommended action for REDHAT-BUG-2292200 is to apply the security updates rather than relying on a workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203