Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filter
Vulnerability Description
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
CWE-1220
Vulnerability Title
Keycloak 权限许可和访问控制问题漏洞
Vulnerability Description
Keycloak是Keycloak组织开源的一种开源身份和访问管理解决方案。 Keycloak存在权限许可和访问控制问题漏洞,该漏洞源于Fine-Grained Admin Permissions (FGAP) v2实现中的权限许可和访问控制问题,导致系统未能根据调用者的特定权限正确过滤子组,使得委托管理员能够查看其未被授权直接访问的子组详细信息,包括组名、路径和自定义属性。
CVSS Information
N/A
Vulnerability Type
N/A