Keycloak是Keycloak组织开源的一种身份和访问管理解决方案。 Keycloak存在授权问题漏洞,该漏洞源于客户端策略执行机制中,系统通过组名而不是唯一标识符检查组成员身份,可能导致具有客户端管理权限的攻击者绕过安全策略,从而注册或更新客户端而不遵循安全强化配置。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | any |
affected |
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Data Grid 8 | any |
unaffected |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
unaffected |
| Red Hat | Red Hat Single Sign-On 7 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Data Grid 8 | - |
cpe:/a:redhat:jboss_data_grid:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18220 | 7.8 HIGH | Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing |
| CVE-2026-18255 | 7.2 HIGH | Quay: quay: global read-only superuser can view robot account tokens |
| CVE-2026-18201 | 5.5 MEDIUM | Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers |
No comments yet