Impact
Keycloak’s Client Policies enforce requirements such as signed JWTs for authentication. Due to a flaw, the system accepts unsigned assertions and receives them as signed, enabling any client with valid credentials to use plain client secrets in place of the mandated signed JWT. This bypass results in an authentication bypass that undermines the administrator’s security policy, potentially allowing an attacker to obtain access to protected resources.
Affected Systems
Vulnerable products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific affected versions were supplied by the CNA, so all currently deployed releases of these products are considered potentially impacted.
Risk and Exploitability
With a CVSS score of 5.4, the vulnerability represents medium severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation, though it is not present in the CISA KEV catalog. The attack requires possession of legitimate client credentials and the ability to send crafted assertion a moderate risk if the policy enforcement is a critical control in their environment.
OpenCVE Enrichment