-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.keycloak:keycloak-services | maven | < 24.0.5 | 24.0.5 |
The GitHub patch explicitly adds authorization checks (requireManageRealm, requireView, requireViewRealm) to these admin endpoints. The absence of these checks in vulnerable versions allowed low-privilege users to access administrative functions: