漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restart
Vulnerability Description
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful exploitation grants the attacker unauthorized access to the victim's account, potentially leading to information disclosure or privilege escalation.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
Keycloak 代码问题漏洞
Vulnerability Description
Keycloak是Keycloak开源的一种开源身份和访问管理解决方案。 Keycloak存在代码问题漏洞,该漏洞源于当启用revokeRefreshToken=true并使用持久会话存储时,服务器重启可重置内部计时机制,可能导致远程攻击者重放先前捕获的用户刷新令牌,即使该令牌已被撤销,成功利用可授予攻击者对受害者账户的未经授权访问,可能导致信息泄露或权限提升。
CVSS Information
N/A
Vulnerability Type
N/A