Impact
The vulnerability resides in the Admin REST API of Keycloak where the per-request in-memory cache resolves clients by unique identifier without checking that the client belongs to the realm specified in the request path. An administrator with limited privileges can therefore read or modify sensitive client configurations that belong to the master realm by performing requests through a realm they control. This can lead to exposure of client credentials or the redirection of administrative login attempts to malicious sites.
Affected Systems
The affected products are Red Hat Build of Keycloak and Red Hat Single Sign-On 7. No specific version numbers are provided, but the flaw applies to all releases of these products that have not been patched by Red Hat.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting that public exploitation is not currently reported. However, the vulnerability can be exploited remotely over the REST API by anyone who has administrative privileges in a realm, allowing the attacker to access client data in other realms. Because no official patch is available at present, the risk remains moderate to potentially high until a fix is deployed.
OpenCVE Enrichment