Uploaded image for project: 'Red Hat build of Keycloak'
  1. Red Hat build of Keycloak
  2. RHBK-4323

Disabled organizations still resolve in organization‑aware login flows [GHI#45874]

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False

      Description

      A business logic error in Keycloak's Organization feature allows users to authenticate into organizations that have been administratively disabled. When a user initiates an organization-aware login flow, disabled organizations remain selectable in the UI and are successfully resolved by the backend, allowing the issuance of tokens within the disabled organization's context.


      This issue was originally tracked in the private repository. Migrated by @abstractj.

              Unassigned Unassigned
              pvlha Pavel Vlha
              Keycloak Core IAM
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: