漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
CVSS Information
N/A
Vulnerability Type
通过发送数据的信息暴露
Vulnerability Title
Red Hat Picketlink和KeyCloak 信息泄露漏洞
Vulnerability Description
Red Hat Picketlink和KeyCloak都是美国红帽(Red Hat)公司的产品。Picketlink是一套用于Java应用程序的统一身份管理框架。Keycloak是一套为现代应用和服务提供身份验证和管理功能的软件。 Red Hat Picketlink和KeyCloak中存在信息泄露漏洞。远程攻击者可通过发送特制的数据利用该漏洞确定系统的属性值。
CVSS Information
N/A
Vulnerability Type
N/A