keycloak-services is vulnerable to Privilege Escalation
82
High Risk
Dynamic Client Registration's allowed-protocol-mapper-type policy only re-validates a mapper's type when its configuration changes. An attacker can register an allowed mapper and later swap its type to a forbidden, high-privilege one while leaving the configuration untouched, bypassing the type restriction. The fix re-validates the mapper type on every update, not only when configuration fields change.
You are affected if you are using a version that falls within the vulnerable range and use Dynamic Client Registration with an Allowed Protocol Mapper Types policy to restrict which mapper types clients can register.
keycloak-services is vulnerable to Privilege Escalation in versions 2.3.0 - 26.7.0.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant