在 Keycloak 身份管理服务的首次登录(first-broker-login)流程中发现了一个漏洞。当用户将社交身份提供商的账户关联到其本地账户时,生成的验证凭证未严格绑定到正在验证的特定上游身份。这使得攻击者可以使用同一社交提供商下的另一个账户,截获该流程,并将自己的账户关联到受害者的本地资料,从而获得未授权的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet