Keycloak Keycloak是Keycloak组织开源的一款身份认证与权限管理软件。 Keycloak 存在授权问题漏洞,该漏洞源于在配置为使用IdP-Initiated流程的SAML代理时未能强制执行SAML断言中的OneTimeUse条件,可能导致攻击者重放有效的未使用断言,劫持用户会话并获取未授权访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | any |
affected |
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
affected |
| Red Hat | Red Hat Single Sign-On 7 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet