REDHAT-BUG-2501724: Medium severity keycloak-services vulnerability
A flaw was found in the token endpoint of keycloak-services. The authorization code payload does not persist the issuing client identifier, and the endpoint relies on a mutable component of the code string to select the client session. An attacker who registers a client in the same realm, establishes an SSO session with a victim user, and intercepts an authorization code issued to a different client can rewrite the client identifier in the code. By redeeming this modified code at the token endpoint, the attacker can obtain tokens for their own client associated with the victim's identity. Successful exploitation allows an attacker to impersonate a user to an attacker-controlled client and access the victim's data exposed to that client.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2501724?
The severity of REDHAT-BUG-2501724 is classified as medium with a score of 4.
How do I fix REDHAT-BUG-2501724?
To mitigate the REDHAT-BUG-2501724 vulnerability, ensure that your Keycloak configuration restricts client registration and review client session handling.
What impact does REDHAT-BUG-2501724 have on keycloak-services?
REDHAT-BUG-2501724 allows an attacker to exploit the token endpoint which may lead to session hijacking under specific conditions.
Who is affected by REDHAT-BUG-2501724?
Users of keycloak-services that allow unauthorized client registrations within the same realm are at risk from REDHAT-BUG-2501724.
When was REDHAT-BUG-2501724 published?
REDHAT-BUG-2501724 was published on July 17, 2026.