在 Keycloak 的第一个 broker 登录流程中发现了一个漏洞。当用户在另一个浏览器中确认账户链接请求时,系统会创建一个临时证明(proof)用于验证该链接。然而,在链接建立之后,或用户随后手动移除链接时,该临时证明未被正确清除。攻击者若控制了外部身份(external identity),可以利用残留的该证明悄悄重新建立链接,从而在无需进一步确认的情况下,非法获取对受害者账户的未授权访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet