REDHAT-BUG-2482460: Medium severity Red Hat Keycloak vulnerability
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2482460?
The severity of REDHAT-BUG-2482460 is classified as medium with a score of 4.
How do I fix REDHAT-BUG-2482460?
To mitigate REDHAT-BUG-2482460, ensure that the signature verification policies are properly configured within Keycloak.
What vulnerable software is impacted by REDHAT-BUG-2482460?
The vulnerability REDHAT-BUG-2482460 affects Red Hat Keycloak.
What is the nature of the vulnerability identified in REDHAT-BUG-2482460?
REDHAT-BUG-2482460 involves improper processing of unsigned claims in JWE encrypted requests, which can lead to unauthorized claims submission.
What are the potential consequences of exploiting REDHAT-BUG-2482460?
Exploitation of REDHAT-BUG-2482460 can allow a remote attacker to bypass security measures and submit unauthorized claims.