CyberRota Analysis
AI-GeneratedKeycloak's authorization services are vulnerable to a flaw that permits users to manipulate time values in their authorization requests, effectively bypassing time-based access restrictions. This could lead to unauthorized access to protected resources outside of designated hours. Organizations utilizing Keycloak for access control should prioritize addressing this vulnerability to mitigate potential security risks.
Original NVD Description
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.
Related CVEs
Other vulnerabilities affecting the same vendor(s)