CyberRota Analysis
AI-GeneratedA vulnerability in the Dynamic Client Registration (DCR) component of Keycloak allows standard users to exploit improper validation of claim paths for User Property mappers, enabling them to write to sensitive internal claim locations. This can lead to the forging of administrative roles within access tokens, allowing attackers to take over other clients, steal confidential information, and potentially gain full administrative control over the realm. Organizations utilizing Keycloak for identity and access management should prioritize addressing this issue to mitigate the risk of unauthorized access and data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Related CVEs
Other vulnerabilities affecting the same vendor(s)