Keycloak 身份与访问管理服务器在动态客户端注册流程中存在一个漏洞。该问题是由于在创建新客户端时,注册过程未能过滤安全敏感的客户端属性所致。拥有有效初始访问令牌的攻击者可以注册一个客户端,该客户端在令牌内省(token introspection)期间可绕过受众(audience)检查。这使得攻击者能够查看同一域(realm)中其他应用访问令牌中的敏感身份信息、角色和会话详情。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105302 | 5.7 MEDIUM | Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access |
| CVE-2026-105301 | 4.0 MEDIUM | Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker |
No comments yet