Keycloak(一种身份和访问管理解决方案)的设备授权授予(Device Authorization Grant)流程中存在一个缺陷。该问题源于令牌兑换过程未能检查用户账户是否因暴力破解保护机制而当前处于锁定状态。如果攻击者持有一个已被锁定的账户的有效会话,他们仍可完成设备登录流程并获取新的安全令牌。这使得攻击者能够在本应暂时禁用以阻止未授权访问的账户上维持访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84042 | 7.8 HIGH | Crun: crun: rootful krun with passt executes container payload as host root |
| CVE-2026-88763 | 5.9 MEDIUM | Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o |
| CVE-2026-88265 | 5.6 MEDIUM | Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and |
| CVE-2026-88264 | 5.6 MEDIUM | Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs |
No comments yet