翻译: 在 Keycloak 服务的 key provider(密钥提供程序)组件中发现了一个缺陷,该组件是 Red Hat Keycloak 版本的核心引擎。由于之前针对路径探测(path probing)的修复不完整,域管理员仍能够提交任意文件系统路径作为 keystore 参数。攻击者可利用此缺陷来确定服务器上文件是否存在以及是否可读,从而可能泄露敏感的系统信息。 关键术语说明: key provider component:密钥提供程序组件 keycloak-services library:keycloa
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet