keycloak-services is vulnerable to Information Disclosure
58
Medium Risk
The Admin REST endpoint GET /admin/realms/{realm}/clients/{clientUuid}/client-secret/rotated returns the vault-resolved plaintext value when a confidential client's rotated secret is stored as a vault placeholder. A delegated administrator with view-clients can therefore read the usable rotated secret instead of the placeholder string. The fix returns the vault placeholder rather than the resolved secret on that endpoint.
You are affected if you are using a version that falls within the vulnerable range and store rotated client secrets in a vault using placeholder references.
keycloak-services is vulnerable to Information Disclosure in versions 26.0.0 - 26.7.1.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant