A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NRed Hat Build Of Keycloak
APPRedhat26.4 – 26.4.14 (excl.)26.6 – 26.6.5 (excl.)Red Hat Data Grid
APPRedhat8.0Red Hat Jboss Enterprise Application Platform Expansion Pack
APPRedhatall versionsRed Hat Single Sign On
APPRedhat7.0
Related vulnerabilities
Brak walidacji nagłówka Host w serwerze Undertow HTTP
XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów
Pominięcie uwierzytelnienia REST w Red Hat DataGrid i Infinispan
Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade
Keycloak: przejęcie konta przez domenę placeholder.org przed wersją 8.0.0