Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-7784

Опубликовано: 18 июл. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

EPSS

Процентиль: 3%
0.00015
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.5
redhat
9 месяцев назад

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

CVSS3: 6.5
debian
9 месяцев назад

A flaw was found in the Keycloak identity and access management system ...

CVSS3: 6.5
github
8 месяцев назад

Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)

EPSS

Процентиль: 3%
0.00015
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-269