CyberRota Analysis
AI-GeneratedA vulnerability exists in the Keycloak server's administrative API, specifically in the group search functionality when Fine-Grained Admin Permissions v2 is enabled. This flaw allows delegated administrators to bypass access restrictions, potentially exposing sensitive attributes and configurations of parent groups by searching for child groups they are authorized to view. Organizations using Keycloak with FGAP v2 enabled should prioritize addressing this issue to mitigate the risk of unauthorized information disclosure.
Original NVD Description
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.
Related CVEs
Other vulnerabilities affecting the same vendor(s)