Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass
Vulnerability Description
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource server, even if they do not have a ticket for those specific resources. This vulnerability requires the resource server to be configured in PERMISSIVE policy enforcement mode and affects typed resources with ownerManagedAccess enabled, where no explicit policy protects the resource type. The primary consequence is unauthorized information disclosure or modification of resources.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Keycloak 授权问题漏洞
Vulnerability Description
Keycloak是Keycloak组织开源的一种开源身份和访问管理解决方案。 Keycloak存在授权问题漏洞,该漏洞源于用户管理访问授权中的访问控制问题,可能导致通过特定权限请求前缀绕过按资源访问控制,从而未经授权访问同一资源服务器内的所有资源。
CVSS Information
N/A
Vulnerability Type
N/A