{"id":"ECHO-b87a-6495-4598","summary":"Flagged by review on PR #19827: this ID needs a documented disposition\nhere, not silent removal, since the raw scanner (matching on\nkeycloak-services@25.0.6's version string alone) will otherwise keep\nreporting it as an open finding forever. Upstream's fix\n(GHSA-gvgg-2r3r-53x7) closes a path where OrganizationMemberResource\ntrusted a client-session note to determine organization membership,\nletting a crafted note forge an org claim. 25.0.6's\nOrganizationMembershipMapper does not have that trust path at all — it\nalways re-verifies membership directly against the organization store\n(provider.getByMember(user)) rather than trusting anything client- or\nsession-supplied. With no client-session-note-based membership check\npresent, the described forgery has no mechanism to exploit here.\n","modified":"2026-09-15T03:42:44.018185469Z","published":"2026-08-30T16:45:31.557Z","withdrawn":"2026-08-31T14:30:19.360Z","upstream":["CVE-2025-1391","GHSA-gvgg-2r3r-53x7"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-1391"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1391"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:2544"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:2545"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-1391"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2346082"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/issues/37169"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/pull/37235"}],"affected":[{"package":{"name":"keycloak-25","ecosystem":"Echo","purl":"pkg:deb/echo/keycloak-25"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.0.6+e2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-b87a-6495-4598.json"}},{"package":{"name":"org.keycloak:keycloak-services","ecosystem":"Echo:Maven","purl":"pkg:maven/org.keycloak/keycloak-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-b87a-6495-4598.json"}}],"schema_version":"1.9.0"}