A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges.
History

Tue, 18 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges.
Title org.keycloak/keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims Keycloak-services: improper authorization in keycloak organization mapper allows unauthorized organization claims
First Time appeared Redhat
Redhat build Keycloak
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References

Mon, 17 Feb 2025 14:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title org.keycloak/keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims
Weaknesses CWE-284
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-02-18T19:29:44.943Z

Reserved: 2025-02-17T08:56:42.702Z

Link: CVE-2025-1391

cve-icon Vulnrichment

Updated: 2025-02-18T17:17:52.617Z

cve-icon NVD

Status : Received

Published: 2025-02-17T14:15:08.413

Modified: 2025-02-17T14:15:08.413

Link: CVE-2025-1391

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-02-17T00:00:00Z

Links: CVE-2025-1391 - Bugzilla