CyberRota Analysis
AI-GeneratedA vulnerability in the group policy evaluation logic of Keycloak allows users to exploit a flawed prefix check for group membership, potentially granting them unauthorized access to administrative functions or protected resources. This issue affects unspecified products utilizing Keycloak for identity and access management. Organizations using Keycloak should prioritize addressing this vulnerability to mitigate the risk of unauthorized access.
Original NVD Description
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group with a similar starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.
Related CVEs
Other vulnerabilities affecting the same vendor(s)