A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Build_of_keycloak | Redhat | - (including) | - (including) |
| Build_of_keycloak | Redhat | 26.2 (including) | 26.2 (including) |
| Build_of_keycloak | Redhat | 26.2.15 (including) | 26.2.15 (including) |
| Build_of_keycloak | Redhat | 26.4 (including) | 26.4 (including) |
| Build_of_keycloak | Redhat | 26.4.11 (including) | 26.4.11 (including) |
| Red Hat build of Keycloak 26.2 | RedHat | rhbk/keycloak-operator-bundle:26.2.15-1 | * |
| Red Hat build of Keycloak 26.2 | RedHat | rhbk/keycloak-rhel9:26.2-18 | * |
| Red Hat build of Keycloak 26.2 | RedHat | rhbk/keycloak-rhel9-operator:26.2-18 | * |
| Red Hat build of Keycloak 26.2.15 | RedHat | rhbk/keycloak-rhel9 | * |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-operator-bundle:26.4.11-1 | * |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-rhel9:26.4-14 | * |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-rhel9-operator:26.4-14 | * |
| Red Hat build of Keycloak 26.4.11 | RedHat | rhbk/keycloak-rhel9 | * |