keycloak-common is vulnerable to Authorization Bypass
76
High Risk
The internal path matcher used by Authorization Services compares raw, unnormalized request URIs against policy patterns. Trailing slashes, matrix parameters, dot-segments, or percent-encoding can make a request match a looser policy than intended and reach a restricted path. The fix normalizes URIs before matching them against authorization policies.
You are affected if you are using a version that falls within the vulnerable range and rely on Authorization Services or policy-enforcer URI-based policies to restrict access to specific paths.
keycloak-common is vulnerable to Authorization Bypass in versions 2.0.0 - 26.7.0.
Upgrade the org.keycloak:keycloak-common library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant