Impact
A flaw in the role‑users endpoint of the keycloak‑services library allows an administrator with insufficient permissions to view private user details such as names and email addresses that should be restricted. The system does not validate that the requester is authorized to see individual user attributes when listing role members, resulting in an exposure of sensitive information. This is a CWE‑639 authorization bias flaw where the application fails to enforce proper access controls to protected resources.
Affected Systems
The vulnerability impacts Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat Data Grid 8, and Red Hat JBoss Enterprise Application Platform Expansion Pack. Exact affected version ranges are not specified, so all supported releases remain candidate targets until a vendor fix is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of < 1 % reflects a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is remote access to the role‑users API over HTTPS, requiring authentication as an administrator—this inference is based on the description of the vulnerability. Exploitation results in information disclosure but does not lead to code execution or full system compromise.
OpenCVE Enrichment