keycloak-services is vulnerable to Privilege Escalation
85
High Risk
Dynamic Client Registration bearer-token authorization trusts resource_access role claims in the presented token without confirming the user actually holds those roles. A standard user can forge admin roles into their own token via a user property mapper and use them against the DCR endpoint to gain elevated client-registration privileges. The fix authorizes DCR from the user's real grants instead of unverified token role claims.
You are affected if you are using a version that falls within the vulnerable range and allow standard users to obtain Initial Access Tokens or otherwise interact with Dynamic Client Registration.
keycloak-services is vulnerable to Privilege Escalation in versions 1.7.0 - 26.7.0.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant