漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.
CVSS Information
N/A
Vulnerability Type
授权机制不恰当
Vulnerability Title
Keycloak oauth 安全漏洞
Vulnerability Description
Keycloak oauth是一套基于OAuth的验证和授权系统,能够提高系统安全开发的安全性。 Keycloak oauth中存在安全漏洞。攻击者可利用该漏洞继续享有已被撤销的权限。
CVSS Information
N/A
Vulnerability Type
N/A