在 Keycloak 的 X.509 客户端证书认证器中发现了一个漏洞。当启用 CRL(证书吊销列表)分发点检查时,服务器未能正确验证客户端证书中提供的文件路径。攻击者可以提供一个特制的证书,诱导服务器尝试从本地系统读取敏感文件,或通过加载超大文件来耗尽内存,从而导致信息泄露或系统崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Single Sign-On 7 | any |
unknown |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96658 | 9.9 CRITICAL | Foreman: safemode bypass leading to rce |
| CVE-2026-96659 | 9.1 CRITICAL | Foreman: excessive permissions for viewer role on preview |
| CVE-2026-86345 | 9.0 CRITICAL | 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to f |
| CVE-2026-12405 | 8.8 HIGH | Rubygem-foreman_remote_execution: command injection in job invocations via effective_user |
| CVE-2026-12540 | 8.2 HIGH | Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter |
| CVE-2026-12541 | 8.2 HIGH | Foreman: command injection in foreman-rake database tasks |
| CVE-2026-12544 | 7.7 HIGH | Foreman: ssti and insecure deserialization in foreman-rake configuration |
| CVE-2026-86344 | 7.5 HIGH | 389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-oper |
| CVE-2026-12423 | 7.5 HIGH | Foreman: unauthenticated information disclosure via provisioning token validation flaw |
| CVE-2026-96577 | 7.1 HIGH | Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without a |
| CVE-2026-12545 | 6.7 MEDIUM | Rubygem-hammer_cli: command injection via insecure editor invocation |
| CVE-2026-56097 | 6.5 MEDIUM | Rubygem-katello: sql injection in registry proxy via labels |
| CVE-2026-83589 | 6.1 MEDIUM | Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect |
| CVE-2026-103754 | 5.9 MEDIUM | Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows |
| CVE-2026-103641 | 5.5 MEDIUM | Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder |
| CVE-2026-12542 | 5.3 MEDIUM | Foreman: command injection in foreman-tail |
| CVE-2026-56098 | 4.3 MEDIUM | Rubygem-katello: improper authorization logic allows resource enumeration |
No comments yet