CyberRota Analysis
AI-GeneratedA vulnerability in the role-users endpoint of the Keycloak identity and access management solution allows restricted administrators to access private user information, including names and email addresses, without proper permissions. This flaw could lead to unauthorized disclosure of sensitive data, impacting user privacy and security. Organizations using Keycloak should prioritize addressing this issue to safeguard user information and maintain compliance with data protection regulations.
Original NVD Description
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.
Related CVEs
Other vulnerabilities affecting the same vendor(s)