Impact
A flaw in the keycloak‑services component allows an attacker with client‑management permissions to bypass configured authentication requirements on confidential clients. The bug stems from improper evaluation of a client’s state during an update operation, letting the attacker first create a public client and later convert it to a confidential client while retaining weaker authentication credentials. This bypass causes the persistence of non‑compliant clients, undermining the realm’s intended hardening and potentially exposing protected resources to unauthorized access.
Affected Systems
The vulnerability affects Red Hat’s builds of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific version numbers are disclosed in the CNA data, so any instance of these products that includes the affected keycloak‑services component should be treated as potentially vulnerable until a fix is released.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only client‑management privileges within a Keycloak realm, so the primary attack vector is privileged‑based within the authentication domain rather than an external network attack. Given these factors, the risk is moderate to low, but remediation is still recommended to prevent policy bypass and unauthorized client configurations.
OpenCVE Enrichment