{"id":"ECHO-b87a-6495-4598","upstream":["CVE-2025-1391","GHSA-gvgg-2r3r-53x7"],"severity":[],"modified":"2026-08-31T14:30:19.360Z","affected":[{"package":{"ecosystem":"Echo","name":"keycloak-25"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.0.6+e2"}]}]},{"package":{"ecosystem":"Echo:Maven","name":"org.keycloak:keycloak-services","purl":"pkg:maven/org.keycloak/keycloak-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-1391"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1391"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:2544"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:2545"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-1391"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2346082"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/issues/37169"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/pull/37235"}],"withdrawn":"2026-08-31T14:30:19.360Z","summary":"Flagged by review on PR #19827: this ID needs a documented disposition\nhere, not silent removal, since the raw scanner (matching on\nkeycloak-services@25.0.6's version string alone) will otherwise keep\nreporting it as an open finding forever. Upstream's fix\n(GHSA-gvgg-2r3r-53x7) closes a path where OrganizationMemberResource\ntrusted a client-session note to determine organization membership,\nletting a crafted note forge an org claim. 25.0.6's\nOrganizationMembershipMapper does not have that trust path at all — it\nalways re-verifies membership directly against the organization store\n(provider.getByMember(user)) rather than trusting anything client- or\nsession-supplied. With no client-session-note-based membership check\npresent, the described forgery has no mechanism to exploit here.\n"}