A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 17 Feb 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges. |
Title | org.keycloak/keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims | Keycloak-services: improper authorization in keycloak organization mapper allows unauthorized organization claims |
First Time appeared |
Redhat
Redhat build Keycloak |
|
CPEs | cpe:/a:redhat:build_keycloak: | |
Vendors & Products |
Redhat
Redhat build Keycloak |
|
References |
|
Mon, 17 Feb 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | org.keycloak/keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-18T19:29:44.943Z
Reserved: 2025-02-17T08:56:42.702Z
Link: CVE-2025-1391

Updated: 2025-02-18T17:17:52.617Z

Status : Received
Published: 2025-02-17T14:15:08.413
Modified: 2025-02-17T14:15:08.413
Link: CVE-2025-1391
