Skip to content

Check if requested user is enabled for impersonation in TE v1#45661

Merged
mposolda merged 1 commit intokeycloak:mainfrom
rmartinc:issue-45651
Jan 22, 2026
Merged

Check if requested user is enabled for impersonation in TE v1#45661
mposolda merged 1 commit intokeycloak:mainfrom
rmartinc:issue-45651

Conversation

@rmartinc
Copy link
Copy Markdown
Contributor

Closes #45651

Just checking if the impersonated user is enabled. I suppose we allow impersonating users that are temporarily disabled (locked by failed attempts). Tests added.

Closes keycloak#45651

Signed-off-by: rmartinc <rmartinc@redhat.com>
Copy link
Copy Markdown
Contributor

@graziang graziang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rmartinc thanks!

@mposolda mposolda self-assigned this Jan 22, 2026
@mposolda mposolda merged commit d67349f into keycloak:main Jan 22, 2026
81 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2025-14559 keycloak-services: Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users

3 participants