Keycloak 身份管理服务在安装提供程序和客户端注册端点中发现了一个安全漏洞。具有只读 view-clients 角色的域管理员可以访问任何机密客户端的活动主密钥,这通常应是受限操作。该暴露的密钥可用于伪装客户端,并未经授权地访问其关联的服务账户权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93017 | 7.7 HIGH | Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and |
| CVE-2026-107466 | 6.1 MEDIUM | Flatpak-builder: local file exfiltration via `file |
| CVE-2026-107445 | 5.4 MEDIUM | Rubygem-katello: katello flatpak remote repositories api cross-organization authorization |
| CVE-2026-107565 | 5.1 MEDIUM | Luksmeta: incomplete gap-boundary and overlap checks in luks1 metadata allocator allow dat |
| CVE-2026-107623 | 4.3 MEDIUM | Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline |
| CVE-2026-107444 | 4.3 MEDIUM | Rubygem-katello: katello docker tags repositories api cross-organization authorization byp |
No comments yet