漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
Vulnerability Description
A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
从可观察状态的可预测
Vulnerability Title
Keycloak 加密问题漏洞
Vulnerability Description
Keycloak是Keycloak组织开源的一款身份认证与权限管理平台。 Keycloak 26.6-12之前版本和26.6.6-1之前版本存在加密问题漏洞,该漏洞源于旧版客户端发起的账户链接端点保护机制使用可预测的哈希,可能导致攻击者伪造有效链接URL,造成账户完全接管,允许攻击者以受害者身份登录。
CVSS Information
N/A
Vulnerability Type
N/A