A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.
2019-10-15T19:15:11.927
2024-11-21T04:27:27.410
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4