ECHO-b87a-6495-4598

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-b87a-6495-4598.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-b87a-6495-4598
Upstream
Withdrawn
2026-08-31T14:30:19.360Z
Published
2026-08-30T16:45:31.557Z
Modified
2026-08-31T15:15:02.910376839Z
Summary
Flagged by review on PR #19827: this ID needs a documented disposition here, not silent removal, since the raw scanner (matching on keycloak-services@25.0.6's version string alone) will otherwise keep reporting it as an open finding forever. Upstream's fix (GHSA-gvgg-2r3r-53x7) closes a path where OrganizationMemberResource trusted a client-session note to determine organization membership, letting a crafted note forge an org claim. 25.0.6's OrganizationMembershipMapper does not have that trust path at all — it always re-verifies membership directly against the organization store (provider.getByMember(user)) rather than trusting anything client- or session-supplied. With no client-session-note-based membership check present, the described forgery has no mechanism to exploit here.
Details
References

Affected packages

Echo / keycloak-25

Package

Name
keycloak-25
Purl
pkg:deb/echo/keycloak-25

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
25.0.6+e2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-b87a-6495-4598.json"

Echo:Maven / org.keycloak:keycloak-services

Package

Name
org.keycloak:keycloak-services
Purl
pkg:maven/org.keycloak/keycloak-services

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://advisory.echohq.com/osv/ECHO-b87a-6495-4598.json"