CVE-2024-3656

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.
Configurations

No configuration.

History

23 Dec 2024, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:3572 -

21 Nov 2024, 09:30

Type Values Removed Values Added
References
  • () https://github.com/hnsecurity/vulns/blob/main/HNS-2024-08-Keycloak.md -
  • () https://news.ycombinator.com/item?id=42136000 -
  • () https://security.humanativaspa.it/an-analysis-of-the-keycloak-authentication-system/ -

10 Oct 2024, 12:51

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Keycloak. Ciertos endpoints en la API REST de administración de Keycloak permiten que usuarios con pocos privilegios accedan a funcionalidades administrativas. Esta falla permite que los usuarios realicen acciones reservadas para administradores, lo que puede provocar violaciones de datos o comprometer el sistema.

10 Oct 2024, 07:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:3575 -

09 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 19:15

Updated : 2024-12-23 14:15


NVD link : CVE-2024-3656

Mitre link : CVE-2024-3656

CVE.ORG link : CVE-2024-3656


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor