QID 983150
QID 983150: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-778x-2mqv-w6xw)
Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-778x-2mqv-w6xw for updates pertaining to this vulnerability.
Vendor References
- GHSA-778x-2mqv-w6xw -
github.com/advisories/GHSA-778x-2mqv-w6xw
CVEs related to QID 983150
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-778x-2mqv-w6xw | org.keycloak:keycloak-core |
|