CVE Published: 09/10/2024 |
CVE Updated: 24/11/2024 |
CVE Year: 2024 Source: redhat |
Vendor: Red Hat |
Product: Red Hat Build of Keycloak Status : PUBLISHED
CVE-2024-3656 Description
A flaw was found in Keycloak. Certain endpoints in Keycloak\'s admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.