漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
Vulnerability Description
A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege escalation and full administrative access to the realm.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
特权授予不正确
Vulnerability Title
Keycloak 权限许可和访问控制问题漏洞
Vulnerability Description
Keycloak是Keycloak组织开源的一种开源身份和访问管理解决方案。 Keycloak存在权限许可和访问控制问题漏洞,该漏洞源于具有`manage-clients`权限的高权限用户通过注入硬编码角色映射器到任意客户端,可绕过现有作用域限制并将`realm-admin`角色注入生成的令牌中,导致权限提升和完全管理访问。
CVSS Information
N/A
Vulnerability Type
N/A