keycloak-services is vulnerable to Account Takeover
73
High Risk
The legacy client-initiated account-linking endpoint at /realms/{realm}/broker/{provider}/link protects requests with a SHA-256 hash built from a nonce, the user session id, the client id, and the identity-provider alias. A malicious OIDC client that can observe or predict those inputs can forge a valid linking URL, and after tricking the victim into authenticating it links the victim's account to an attacker-controlled external identity. That yields full account takeover so the attacker can sign in as the victim. The fix disables the legacy endpoint by default and requires migrating to Application-Initiated Actions (idp_link).
You are affected if you are using a version that falls within the vulnerable range and clients use the legacy client-initiated account linking endpoint.
keycloak-services is vulnerable to Account Takeover in versions 1.0.1 - 26.7.1.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant