Impact
The flaw lies in the dynamic client registration process of Keycloak, where the system fails to filter security‑sensitive client attributes when creating a new client. An attacker who possesses a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to read sensitive identity data, role memberships, and session details from access tokens issued to other applications within the same realm, effectively enabling unauthorized disclosure of protected information.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific version numbers are listed in the advisory, so any deployment of these products may be impacted until an official fix is available.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is unavailable, suggesting that exploitation likelihood has not been quantified. The vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to possess a valid Initial Access Token, which means the attacker must have some level of access to the system. The attacker can abuse the flaw to gain unauthorized information from tokens belonging to other applications within the same realm. Because the exploitation path depends on an existing privileged token, the overall risk is moderate but the potential impact of the information disclosure is significant.
OpenCVE Enrichment