Lucene search

K
osvGoogleOSV:GHSA-8PRC-58J4-M55Q
HistoryMay 24, 2022 - 4:58 p.m.

Keycloak Unauthenticated Access

2022-05-2416:58:47
Google
osv.dev
6

0.001 Low

EPSS

Percentile

37.2%

A flaw was found in the Keycloak REST API before version 8.0.0, implemented in Keycloak before 7.0.1 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.

0.001 Low

EPSS

Percentile

37.2%