Impact
A flaw in Keycloak’s Fine‑Grained Admin Permissions (FGAP v2) allows an administrator who can view a role to see all groups attached to that role, even if the administrator lacks permission to view those groups. The missing check exposes hidden group names and custom settings, potentially revealing sensitive deployment details. This is an instance of CWE‑284 (Improper Access Control) and constitutes information disclosure to an authenticated privileged user.
Affected Systems
Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific affected version information is provided by the CNA.
Risk and Exploitability
The CVSS score is 4.3, indicating a low‑severity information disclosure. The EPSS score is less than 1 %, showing a very low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. The flaw represents an Improper Access Control (CWE‑284) weakness, allowing an attacker authenticated as an administrator with role‑view permission to discover hidden group metadata. The likely attack vector is through the administrative web interface; an attacker would need to be authenticated as an administrator with role‑view permission. Because the system does not enforce a group‑view check, any privileged user can uncover hidden group metadata, but the impact remains limited to information exposure rather than full system control.
OpenCVE Enrichment