QID 980198
QID 980198: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-c9x9-xv66-xp3v)
A flaw was found in Keycloak, where it would permit a user with a view-profile role to manage the resources in the new account console. This flaw allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c9x9-xv66-xp3v for updates pertaining to this vulnerability.
Vendor References
- GHSA-c9x9-xv66-xp3v -
github.com/advisories/GHSA-c9x9-xv66-xp3v
CVEs related to QID 980198
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c9x9-xv66-xp3v | org.keycloak:keycloak-core |
|