Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-7784

Опубликовано: 18 июл. 2025
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate. While the flaw requires an already privileged user, with manage-users, and an FGAPv2-enabled realm, successful exploitation allows complete administrative takeover of a Keycloak realm. This could lead to unauthorized changes to users, roles, and realm configurations. The vulnerability is particularly concerning in environments where multiple administrative users have restricted scopes.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected
Red Hat build of Keycloak 26keycloak-servicesFixedRHSA-2025:1201529.07.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-operator-bundleFixedRHSA-2025:1201629.07.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-rhel9FixedRHSA-2025:1201629.07.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-rhel9-operatorFixedRHSA-2025:1201629.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2381861org.keycloak/keycloak-services: Privilege Escalation in Keycloak Admin Console (FGAPv2 Enabled)

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
18 дней назад

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

CVSS3: 6.5
debian
18 дней назад

A flaw was found in the Keycloak identity and access management system ...

CVSS3: 6.5
github
6 дней назад

Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)

6.5 Medium

CVSS3