CyberRota Analysis
AI-GeneratedA vulnerability exists in the keycloak-services component of Keycloak, allowing an attacker with client management permissions to bypass authentication policies by manipulating client configurations. Specifically, an attacker can create a public client and subsequently change it to a confidential client, undermining the realm's security hardening measures. Organizations utilizing Keycloak for authentication and authorization should prioritize addressing this issue to prevent unauthorized access and ensure compliance with security protocols.
Original NVD Description
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.
Related CVEs
Other vulnerabilities affecting the same vendor(s)