CVE-2024-3656: Red Hat Build Of Keycloak

High severity, CVSS 8.1. EPSS: 2.9% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.

Affected products

  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat Single Sign-On 7

Published 2024-10-09. Last modified 2026-10-09.