Description
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3212 | A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks. |
Github GHSA |
GHSA-8prc-58j4-m55q | Keycloak Unauthenticated Access |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T00:26:39.131Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14832
No data.
Status : Modified
Published: 2019-10-15T19:15:11.927
Modified: 2024-11-21T04:27:27.410
Link: CVE-2019-14832
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA