Impact
A flaw exists in the JWT Bearer authorization grant inside the keycloak-services component of Red Hat Build of Keycloak. The grant does not verify that a client has a user consent requirement before issuing a token. Consequently, an authenticated attacker who possesses valid client credentials and a trusted identity‑provider assertion can obtain a token that grants access to a user account at a client that normally requires consent.
Affected Systems
The vulnerability affects the keycloak-services component of Red Hat Build of Keycloak and is also present in Red Hat Single Sign‑On 7. No specific product versions are listed; the issue is documented for the Red Hat Build of Keycloak and RHEL SSO 7 packages.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score is not available; the vulnerability is not listed in the CISA KEV catalog. Attackers need to be authenticated and possess valid client credentials, and must be able to present a trusted identity‑provider assertion. If an attacker can meet these prerequisites, they can bypass the consent requirement and acquire a token that provides unauthorized access to a user account at a consent‑gated client. The risk is therefore moderate, contingent on the attacker’s ability to obtain suitable client credentials and a trusted assertion.
OpenCVE Enrichment