Impact
Based on the description, the flaw lies in the keycloak‑services component, where validation of masked client secrets during an OIDC identity‑provider update is insufficient. When a delegated administrator changes the token URL using the sentinel value that masks the real secret, Keycloak mistakenly reuses the existing secret. It is inferred that this defect permits an attacker to set a malicious token URL, causing the real secret to be exposed or captured, and then use the compromised secret to forge authentication tokens or impersonate the identity provider, leading to unauthorized access to protected resources.
Affected Systems
Red Hat Build of Keycloak (various versions), Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. The flaw applies to any installation of these products where OIDC identity‑provider updates can be performed by delegated administrators.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires the attacker to have delegated administrative privileges to edit an OIDC identity provider and the ability to modify the token URL to a malicious endpoint. Once the secret is captured, the attacker can impersonate the identity provider to gain unauthorized authentication. The attack path is confined to the administrative scope of the application and does not permit arbitrary code execution.
OpenCVE Enrichment