Описание
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
Отчет
Red Hat Product Security has rated this vulnerability as having a security impact of Important. This issue allows authenticated users to bypass fine-grained authorization controls by exploiting a lack of URI normalization in the PathMatcher utility. While authentication is required, the ability to bypass explicit "Deny" policies and access restricted resources poses a significant risk to the confidentiality and integrity of the protected system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Data Grid 8 | keycloak-services | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-services | Affected | ||
| Red Hat Single Sign-On 7 | keycloak-services | Fix deferred | ||
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle | Fixed | RHSA-2026:50847 | 05.08.2026 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:50847 | 05.08.2026 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator | Fixed | RHSA-2026:50847 | 05.08.2026 |
| Red Hat build of Keycloak 26.4.14 | keycloak-services | Fixed | RHSA-2026:50846 | 05.08.2026 |
| Red Hat build of Keycloak 26.4.14 | rhbk-openshift-rhel9/rhbk-openshift-rhel9 | Fixed | RHSA-2026:50846 | 05.08.2026 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle | Fixed | RHSA-2026:50849 | 05.08.2026 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:50849 | 05.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
A flaw was found in Keycloak's Authorization Services. The component r ...
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
EPSS
8.1 High
CVSS3