A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication factor along with an existing one and bypass authentication.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat build of Keycloak 22 | RedHat | rhbk/keycloak-operator-bundle:22.0.10-1 | * |
Red Hat build of Keycloak 22 | RedHat | rhbk/keycloak-rhel9:22-13 | * |
Red Hat build of Keycloak 22 | RedHat | rhbk/keycloak-rhel9-operator:22-16 | * |
Red Hat build of Keycloak 22.0.10 | RedHat | keycloak | * |
RHSSO 7.6.8 | RedHat | * |