Permissions, Privileges, and Access Controls in Keycloak - CVE-2024-3656
Published: June 24, 2024
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improperly imposed security restrictions on the administrative features. A remote low privileged user can utilize administrative functionalities within Keycloak admin interface and escalate privileges within the application.
Affected software
Dell Data Protection Central
How to mitigate CVE-2024-3656
Dell Data Protection Central - update to 19.12.0-2