Keycloak 的 OIDC 动态客户端注册(DCR)组件中发现了一个缺陷。该组件在响应序列化过程中存在一个 bug,导致“反向通道注销时的离线令牌吊销”设置未被包含在响应中。当客户端执行标准更新操作时,由于缺少该信息,此设置会被静默禁用。因此,即使用户会话通过反向通道注销被终止,离线令牌仍可能保持有效。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Single Sign-On 7 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89091 | 8.8 HIGH | Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows a |
| CVE-2026-93017 | 7.7 HIGH | Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and |
| CVE-2026-107466 | 6.1 MEDIUM | Flatpak-builder: local file exfiltration via `file |
| CVE-2026-107651 | 5.5 MEDIUM | Eog: eog: arbitrary code execution via heap buffer overflow in png metadata reader |
| CVE-2026-107445 | 5.4 MEDIUM | Rubygem-katello: katello flatpak remote repositories api cross-organization authorization |
| CVE-2026-107565 | 5.1 MEDIUM | Luksmeta: incomplete gap-boundary and overlap checks in luks1 metadata allocator allow dat |
| CVE-2026-107604 | 4.9 MEDIUM | Keycloak-services: keycloak-services: view-clients role allows retrieval of active client |
| CVE-2026-107444 | 4.3 MEDIUM | Rubygem-katello: katello: katello: katello docker tags repositories api cross-organization |
No comments yet