Keycloak vulnerable to two factor authentication bypass
Moderate severity
GitHub Reviewed
Published
Apr 30, 2025
in
keycloak/keycloak
•
Updated Apr 30, 2025
Description
Published to the GitHub Advisory Database
Apr 30, 2025
Reviewed
Apr 30, 2025
Last updated
Apr 30, 2025
Description
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
References