A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Redhat Build_Of_Keycloak
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
|
26.4
|
26.4.14
|
|
Redhat Build_Of_Keycloak
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
|
26.6
|
26.6.5
|