pac4j-core 在 6.5.6 之前的版本中, 存在一个认证绕过漏洞,其根源在于反转了配置文件类型(profile type)的验证逻辑。攻击者可以通过较弱的客户端完成认证,从而访问需要更强配置文件类型的资源,只要他们能满足通用的配置文件检查条件即可。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82461 | 8.1 HIGH | pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token |
| CVE-2026-82462 | 6.5 MEDIUM | pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution |
| CVE-2026-82464 | 6.1 MEDIUM | pac4j-core before 6.5.6 Open Redirect via Backslash Logout |
| CVE-2026-82465 | 5.3 MEDIUM | pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest |
No comments yet