Keycloak has lack of validation of access token on client registrations endpoint
Moderate severity
GitHub Reviewed
Published
Jan 12, 2023
in
keycloak/keycloak
•
Updated Jan 23, 2023
Description
Published to the GitHub Advisory Database
Jan 12, 2023
Reviewed
Jan 12, 2023
Published by the National Vulnerability Database
Jan 13, 2023
Last updated
Jan 23, 2023
When a service account with the create-client or manage-clients role can use the client-registration endpoints to create/manage clients with an access token.
If the access token is leaked, there is an option to revoke the specific token. However, the check is not performed in client-registration endpoints.
References