Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-7784

Опубликовано: 18 июл. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

EPSS

Процентиль: 1%
0.00012
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.5
redhat
4 месяца назад

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

CVSS3: 6.5
debian
4 месяца назад

A flaw was found in the Keycloak identity and access management system ...

CVSS3: 6.5
github
3 месяца назад

Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)

EPSS

Процентиль: 1%
0.00012
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269