目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-18217— Keycloak 输入验证错误漏洞

CVSS 3.4 · Low EPSS 0.19% · P9

Affected Version Matrix 6

ベンダープロダクトVersion Rangeステータス
Red HatRed Hat Build of Keycloakanyaffected
anyaffected
anyaffected
Red HatRed Hat Data Grid 8anyunaffected
Red HatRed Hat JBoss Enterprise Application Platform Expansion Packanyunaffected
Red HatRed Hat Single Sign-On 7anyunaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-18217の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution
ソース: CVE Program / CVE List V5
脆弱性説明
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
输入验证不恰当
ソース: CVE Program / CVE List V5
脆弱性タイトル
Keycloak 输入验证错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Keycloak是Keycloak组织开源的一种身份和访问管理解决方案。 Keycloak存在输入验证错误漏洞,该漏洞源于SAML协议实现处理HTTP-Redirect绑定的认证请求时存在缺陷,如果客户端配置了通配符重定向URL,攻击者可构造包含恶意参数的请求,导致合法响应被附加到攻击者参数上,可能使服务提供商处理攻击者数据,导致用户登录到错误账户。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Data Grid 8-cpe:/a:redhat:jboss_data_grid:8
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack-cpe:/a:redhat:jbosseapxp
Red HatRed Hat Single Sign-On 7-cpe:/a:redhat:red_hat_single_sign_on:7

II. CVE-2026-18217の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-18217のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-18217 厂商安全公告 (2)

Same Patch Batch · Red Hat · 2026-07-31 · 14 CVEs total

CVE-2026-100798.5 HIGHStackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injecti
CVE-2026-181418.2 HIGHAap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http he
CVE-2026-157227.5 HIGH389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_
CVE-2026-117707.5 HIGH389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
CVE-2026-182156.8 MEDIUMKeycloak-services: keycloak-services: microsoft external access-token exchange bypasses co
CVE-2026-182146.8 MEDIUMKeycloak-services: keycloak-services: google external access-token exchange bypasses hoste
CVE-2026-182086.5 MEDIUMKeycloak-services: keycloak-services: inactive out-of-audience token introspection leaks s
CVE-2026-182036.5 MEDIUMKeycloak-services: keycloak-services: group policy extendchildren matches sibling group pa
CVE-2026-161054.9 MEDIUMKeycloak-services: keycloak-services: missing per-role authorization on rolecontainerresou
CVE-2026-182184.2 MEDIUMKeycloak-services: keycloak-services: client not-before revocation ignored when realm not-
CVE-2026-182114.2 MEDIUMKeycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefi
CVE-2026-182063.7 LOWKeycloak-services: keycloak-services: client policy source-host wildcard domain matching b
CVE-2026-182093.4 LOWKeycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter

IV. 関連脆弱性

V. CVE-2026-18217へのコメント

まだコメントはありません


コメントを残す