Keycloak 提供了一个称为 mTLS holder-of-key 绑定的功能,该功能通过将令牌与客户端的数字证书绑定,确保令牌只能由最初请求该令牌的客户端使用。然而,研究人员发现一个缺陷:新的标准令牌交换 V2(Standard Token Exchange V2)功能未进行此证书检查。这导致攻击者利用窃取的客户端凭据,可以获取一个标准的、不受限制的令牌,从而绕过上述安全保护机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93834 | 8.8 HIGH | Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape |
| CVE-2026-96448 | 6.6 MEDIUM | Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privileg |
No comments yet