在 Keycloak 的 X.509 客户端证书身份验证器中发现了一个缺陷,Keycloak 是一款用于身份和访问管理解决方案。问题出现在服务器配置为使用 CRL 分发点或 OCSP 来检查证书吊销的情况。攻击者可以提供一个指向恶意服务器的特殊构造证书,导致 Keycloak 在证书完全验证之前向内部或外部端点发起未授权的出站请求。这可能导致盲服务器端请求伪造(SSRF)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105306 | 6.5 MEDIUM | Keycloak-services: keycloak-services: token introspection audience bypass via dynamic clie |
| CVE-2026-105302 | 5.7 MEDIUM | Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access |
No comments yet