Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Vulnerability Type
从可观察状态的可预测
Vulnerability Title
Red Hat Keycloak operator 安全漏洞
Vulnerability Description
Red Hat Keycloak是美国红帽(Red Hat)公司的一套为现代应用和服务提供身份验证和管理功能的软件。Keycloak operator是一款用于在Keycloak创建和同步资源的工具。 Red Hat Keycloak operator 8.0.2之前版本(仅社区版)中存在安全漏洞,该漏洞源于在安装Keycloak时,程序会生成一个随机的管理员密码,但当其部署在相同的OpenShift名称空间时,该管理员密码不变。攻击者可利用该漏洞绕过访问限制。
CVSS Information
N/A
Vulnerability Type
N/A