CyberRota Analysis
AI-GeneratedA vulnerability exists in Keycloak's administrative API, allowing an administrator with the ability to manage identity providers to link a new provider to an organization without the necessary permissions. This could enable unauthorized access and manipulation of user login methods for specific organizations, potentially compromising user authentication processes. Organizations using Keycloak should prioritize addressing this issue to safeguard their identity management systems.
Original NVD Description
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.
Related CVEs
Other vulnerabilities affecting the same vendor(s)