Impact
A flaw in the client policy enforcement of Keycloak, identified as an access control weakness (CWE-285), causes group membership to be verified by group name instead of a unique identifier. An attacker who possesses client‑management privileges can add a group that shares a name with an existing policy group in another portion of the hierarchy, enabling the attacker to register or update clients without following the required security hardening profiles.
Affected Systems
Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7 are affected. Exact product versions that contain the fix are not listed in the provided information.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 and an EPSS score of less than 1%, indicating moderate severity but very low likelihood of exploitation today. It is not listed in the CISA KEV catalog. The attack requires client‑management privileges and the ability to create or modify groups; it does not require remote code execution or user interaction beyond normal administrative actions. No public workaround meets Red Hat’s security criteria at this time.
OpenCVE Enrichment