Логотип exploitDog
bind:CVE-2025-14777
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-14777

Количество 3

Количество 3

nvd логотип

CVE-2025-14777

около 2 месяцев назад

A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for authorization resource management, specifically in ResourceSetService and PermissionTicketService. The system checks authorization against the resourceServer (client) ID provided in the API request, but the backend database lookup and modification operations (findById, delete) only use the resourceId. This mismatch allows an authenticated attacker with fine-grained admin permissions for one client (e.g., Client A) to delete or update resources belonging to another client (Client B) within the same realm by supplying a valid resource ID.

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2025-14777

около 2 месяцев назад

A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerab ...

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-4cj5-g32w-86fv

около 2 месяцев назад

A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for authorization resource management, specifically in ResourceSetService and PermissionTicketService. The system checks authorization against the resourceServer (client) ID provided in the API request, but the backend database lookup and modification operations (findById, delete) only use the resourceId. This mismatch allows an authenticated attacker with fine-grained admin permissions for one client (e.g., Client A) to delete or update resources belonging to another client (Client B) within the same realm by supplying a valid resource ID.

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-14777

A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for authorization resource management, specifically in ResourceSetService and PermissionTicketService. The system checks authorization against the resourceServer (client) ID provided in the API request, but the backend database lookup and modification operations (findById, delete) only use the resourceId. This mismatch allows an authenticated attacker with fine-grained admin permissions for one client (e.g., Client A) to delete or update resources belonging to another client (Client B) within the same realm by supplying a valid resource ID.

CVSS3: 6
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-14777

A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerab ...

CVSS3: 6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4cj5-g32w-86fv

A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for authorization resource management, specifically in ResourceSetService and PermissionTicketService. The system checks authorization against the resourceServer (client) ID provided in the API request, but the backend database lookup and modification operations (findById, delete) only use the resourceId. This mismatch allows an authenticated attacker with fine-grained admin permissions for one client (e.g., Client A) to delete or update resources belonging to another client (Client B) within the same realm by supplying a valid resource ID.

CVSS3: 6
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу