Back

MEDIUM

Keycloak: authorization bypass

Published Apr 25, 2024

Description

A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.

Affected products

Remediation

Vendor solution

No mitigation is currently available for this flaw.

Red Hat statement

Due to the high complexity of this attack, Red Hat considers this a Moderate impact.

Red Hat mitigation

No mitigation is currently available for this flaw.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 25, 2024
Updated Nov 11, 2025
Reserved Dec 6, 2023
CISA Vulnrichment
Updated Apr 25, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 16, 2024
GHSA-46C8-635V-68R2