Keycloak(一种开源的身份与访问管理解决方案)的动态客户端注册服务中存在一个缺陷。当拥有“view-clients”(查看客户端)角色的用户访问客户端注册端点以获取客户端详情时,会触发该问题。由于未能对敏感信息进行掩码处理,服务会以明文形式返回客户端的机密密钥(confidential secret)。这使得只读管理员能够获取受影响客户端账户的完整访问权限,并可能在当前 Realm(领域)内进一步提升其权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89060 | 7.7 HIGH | Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multiclu |
| CVE-2026-18495 | 6.1 MEDIUM | Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough |
| CVE-2026-77159 | 5.5 MEDIUM | Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership chan |
| CVE-2026-88914 | 4.4 MEDIUM | Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea |
No comments yet