Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change
Vulnerability Description
A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
CWE-1288
Vulnerability Title
Keycloak 输入验证错误漏洞
Vulnerability Description
Keycloak是Keycloak组织开源的一种身份和访问管理解决方案。 keycloak存在输入验证错误漏洞,该漏洞源于keycloak-services组件处理身份提供者管理时输入验证不当,当委托管理员使用掩码的客户端秘密标记值更新OIDC身份提供者时,即使令牌URL等安全敏感字段已被更改,Keycloak仍重用现有的真实秘密,允许攻击者重定向并捕获该秘密。
CVSS Information
N/A
Vulnerability Type
N/A