keycloak-services is vulnerable to Authorization Bypass
45
Medium Risk
Under Fine-Grained Admin Permissions v2, the role-to-group mapping enumeration in RoleContainerResource checks that the caller can view the role but does not check per-group view permission for groups assigned to that role. A delegated admin who can view a role can therefore list hidden groups mapped to it and read their names, paths, and custom attributes. The fix enforces group view permissions when returning those role-group mappings.
You are affected if you are using a version that falls within the vulnerable range and use Fine-Grained Admin Permissions v2 to restrict which admins can view groups.
keycloak-services is vulnerable to Authorization Bypass in versions 26.2.0 - 26.7.1.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant