keycloak-services is vulnerable to Improper Verification of Cryptographic Signature
58
Medium Risk
OIDC request-object processing accepts a JWE-encrypted request object whose decrypted plaintext is unsigned raw JSON and honors those claims without enforcing the client's configured requestObjectSignatureAlg. An attacker can submit encrypted-but-unsigned claims and advance the authorization flow as if the request object were signed, violating OIDC Core and FAPI signing requirements. The redirect URI allowlist remains a compensating control. The fix rejects JWE request objects whose decrypted content is not a properly signed JWS when a signature algorithm is required.
You are affected if you are using a version that falls within the vulnerable range and have clients configured with requestObjectSignatureAlg to require signed request objects.
keycloak-services is vulnerable to Improper Verification of Cryptographic Signature in versions 15.0.0 - 26.7.0.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant