Lack of data validation In org.keycloak:keycloak-services
Description
Keycloak Authorization Bypass vulnerability Due to a permissive regular expression hardcoded for filtering allowed hosts to register a dynamic client, a malicious user with enough information about the environment could benefit and jeopardize an environment with this specific Dynamic Client Registration with TrustedDomain configuration previously unauthorized.
Acknowledgements:
Special thanks to Bastian Kanbach for reporting this issue and helping us improve our security.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 22.0.10, 24.0.3 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13.
References
1. 2.