keycloak-services is vulnerable to Authorization Bypass
44
Medium Risk
Under Fine-Grained Admin Permissions v2, the group search path on GET /admin/realms/{realm}/groups builds hierarchy results without filtering parent groups by the caller's view permissions. A delegated admin who can view a child group can therefore receive the full parent group representation in the search response, including names, paths, and custom attributes they are not allowed to access directly. The fix redacts or omits parent groups the caller is not authorized to view when constructing search hierarchy results.
You are affected if you are using a version that falls within the vulnerable range and use Fine-Grained Admin Permissions v2 to restrict which admins can view groups in a hierarchy.
keycloak-services is vulnerable to Authorization Bypass in versions 26.2.0 - 26.7.1.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant