CVE-2024-3656
HIGH NUCLEIKeycloak < 24.0.5 - Authenticated Privilege Escalation via Admin REST API Endpoints
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-3656. PoCs published by h4x0r-dz. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-3656, a Broken Access Control vulnerability in Keycloak < 24.0.5. It includes a patch diff analysis, reproduction steps, and HTTP request examples for exploiting the `testLDAPConnection` endpoint.
Description
A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2024-3656, a Broken Access Control vulnerability in Keycloak < 24.0.5. It includes a patch diff analysis, reproduction steps, and HTTP request examples for exploiting the `testLDAPConnection` endpoint.
Nuclei Templates (1)
http.favicon.hash:"-1105083093" || http.html:"keycloak" || http.title:"keycloak"
icon_hash=-1105083093 || body="keycloak" || title="keycloak"
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N