CVE-2019-14832

HIGH

Keycloak < 8.0.0 - Authenticated Incorrect Authorization via Realm Access Bypass

Title source: llm
STIX 2.1

Description

A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14832

Scores

CVSS v3 7.5
EPSS 0.0038
EPSS Percentile 59.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (3)
org.keycloak/keycloak-model-infinispan 0 - 7.0.1Maven
org.keycloak/keycloak-model-jpa 0 - 7.0.1Maven
redhat/keycloak < 7.0.1
Published Oct 15, 2019
Tracked Since Feb 18, 2026