Red Hat build of Keycloak是美国红帽(Red Hat)公司的一款用于单点登录的Web应用。 Red Hat Build of Keycloak存在访问控制错误漏洞,该漏洞源于User-Managed Access资源集端点访问控制不当,可能导致未经授权的资源修改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4647 | 6.1 MEDIUM | Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library |
| CVE-2026-1940 | 5.1 MEDIUM | Gstreamer: incomplete fix of cve-2026-1940 |
| CVE-2026-4633 | 3.7 LOW | Keycloak: keycloak: user enumeration via differential error messages |
No comments yet