Red Hat Build of Keycloak
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*
- rhbk-26.4
An improper access control vulnerability has been identified in Keycloak's User-Managed Access (UMA) resource_set endpoint. This flaw allows authenticated attackers to bypass the allowRemoteResourceManagement=false restriction, enabling unauthorized modifications of protected resources. The issue arises from incomplete enforcement of access control checks on PUT operations to the resource_set endpoint, impacting data integrity.
Exploitation of this vulnerability allows authenticated users to make unauthorized changes to protected resources, thereby compromising data integrity.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.