Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Arqit SKA-Platform Improper Handling of Parameters Vulnerability
Vulnerability Description
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
CVSS Information
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Vulnerability Type
参数问题
Vulnerability Title
Arqit Symmetric Key Agreement Platform 安全漏洞
Vulnerability Description
Arqit Symmetric Key Agreement Platform是Arqit公司的一个量子安全密钥协商平台。 Arqit Symmetric Key Agreement Platform 26.03之前版本存在安全漏洞,该漏洞源于Keycloak接口中空闲超时参数管理不当,可能导致攻击者通过未过期的浏览器会话冒充经过身份验证的租户用户。
CVSS Information
N/A
Vulnerability Type
N/A