Uploaded image for project: 'RH-SSO'
  1. RH-SSO
  2. RHSSO-1301

[7.2.z] User with "manage-users" role can self-assign the "realm-admin" role to have full administrative control of the realm configuration

    XMLWordPrintable

Details

    Description

      This is regression of KEYCLOAK-528 which was marked as fixed in Keycloak 3.2.0.CR1

      A customer using RH-SSO 7.2.0.GA release for Openshift image reported the same.

      I have reproduced the issue internally on RH-SSO 7.2.1 as well.

      The issue seems to only work when using the master realm. But it is still reproducible if another 'test' realm is used in RH-SSO 7.2

      Please refer to the attached screenshots capture that show the behavior.

      Attachments

        Activity

          People

            hmlnarik@redhat.com Hynek Mlnařík
            rhn-support-igueye Issa Gueye
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: