Impact
An issue in the keycloak-services component of Keycloak allows a realm administrator to configure a wildcard domain policy (e.g., *.example.com) intended to limit which hosts can register or update clients. The component fails to correctly validate hostnames and accepts any hostname that ends with the specified suffix, even if the name is not an approved subdomain. An attacker who can manipulate the reverse DNS entry of the connection thereby names a hostname that satisfies the suffix is able to bypass the host‑based restriction and alter or create client configurations without authorization.
Affected Systems
Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. The vulnerable component is keycloak-services; the specific build and patch level are not listed, so any release containing this component before the fix is potentially affected.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity. The EPSS score of 0.00216, or 0.216%, indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no effective official workaround is available. Nonetheless, exploitation requires the attacker to control reverse DNS for the connection, which is a relatively high‑bar attack that can be executed remotely. If the host‑based restriction is bypassed, the attacker can modify or create client configurations, undermining the integrity of identity and access management within the affected realm.
OpenCVE Enrichment