PT-2026-93414 · Red Hat+1 · Keycloak+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
apache-airflow-providers-keycloak versions prior to 0.10.0
Description
The unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, rather than restricting it to the client configured for Airflow. Because no allowlist restricts which client IDs may authenticate, credentials from an unrelated application sharing the same realm are accepted as valid Airflow login credentials, allowing Airflow to mint a signed session token for that application's service account. Additionally, the endpoint allows unauthenticated credential guesses against Keycloak using Airflow's identity. This issue affects deployments using the Keycloak auth manager where the realm is shared with other confidential clients. An attacker with valid credentials for any of those clients can gain access to any endpoint that requires authentication, as well as permissions held by that specific service account.
Recommendations
Upgrade to version 0.10.0 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak
Apache Airflow Providers Keycloak