Описание
A flaw was found in Keycloak. An administrator with manage-users permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
Отчет
This vulnerability is rated Moderate for Red Hat. An administrator with manage-users permission can modify unmanaged user attributes in Keycloak, even when the "Only administrators can view" setting is enabled. This bypass requires the realm to be configured with unmanaged attributes set to "Only administrators can view" and the administrator to possess manage-users permission.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-services | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-services | Fix deferred | ||
| Red Hat Single Sign-On 7 | keycloak-services | Fix deferred | ||
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle | Fixed | RHSA-2026:2366 | 09.02.2026 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:2366 | 09.02.2026 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator | Fixed | RHSA-2026:2366 | 09.02.2026 |
| Red Hat build of Keycloak 26.4.9 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:2365 | 09.02.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.9 Medium
CVSS3
Связанные уязвимости
A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
A flaw was found in Keycloak. An administrator with `manage-users` per ...
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes
EPSS
4.9 Medium
CVSS3