Red Hat Keycloak是美国红帽(Red Hat)公司的一套为现代应用和服务提供身份验证和管理功能的软件。 Red Hat Keycloak offline_access存在安全漏洞,该漏洞源于缺少root会话验证,以及跨root和用户重用会话 ID,攻击者能够解析附加到先前经过身份验证的用户的用户会话,在使用刷新令牌时,他们将获得原始用户的令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7.6
|
|
| Red Hat | Red Hat Single Sign-On 7.6.1 | - |
cpe:/a:redhat:red_hat_single_sign_on:7.6.1
|
|
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 7 | 0:18.0.3-1.redhat_00002.1.el7sso ~ * |
cpe:/a:redhat:red_hat_single_sign_on:7.6::el7
|
|
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 7 | 0:18.0.6-1.redhat_00001.1.el7sso ~ * |
cpe:/a:redhat:red_hat_single_sign_on:7.6::el7
|
|
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 8 | 0:18.0.3-1.redhat_00002.1.el8sso ~ * |
cpe:/a:redhat:red_hat_single_sign_on:7.6::el8
|
|
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 8 | 0:18.0.6-1.redhat_00001.1.el8sso ~ * |
cpe:/a:redhat:red_hat_single_sign_on:7.6::el8
|
|
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 9 | 0:18.0.3-1.redhat_00002.1.el9sso ~ * |
cpe:/a:redhat:red_hat_single_sign_on:7.6::el9
|
|
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 9 | 0:18.0.6-1.redhat_00001.1.el9sso ~ * |
cpe:/a:redhat:red_hat_single_sign_on:7.6::el9
|
|
| Red Hat | RHEL-8 based Middleware Containers | 7.6-15 ~ * |
cpe:/a:redhat:rhosemc:1.0::el8
|
|
| Red Hat | RHEL-8 based Middleware Containers | 7.6-20 ~ * |
cpe:/a:redhat:rhosemc:1.0::el8
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-4853 | 8.1 HIGH | Quarkus: http security policy bypass |
| CVE-2022-3596 | 7.5 HIGH | Instack-undercloud: rsync leaks information to undercloud |
| CVE-2022-1438 | 6.4 MEDIUM | Keycloak: xss on impersonation under specific circumstances |
No comments yet