脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2
脆弱性説明
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
脆弱性タイプ
N/A
脆弱性タイトル
Red Hat Build of Keycloak 安全漏洞
脆弱性説明
Red Hat build of Keycloak是美国Red Hat公司开源的一款用于单点登录的Web应用。 Red Hat Build of Keycloak存在安全漏洞,该漏洞源于default-groups REST endpoint和realm representation组件问题,可能导致具有realm查看权限的委派管理员查看隐藏默认组的名称和标识符,从而暴露敏感的组织结构或内部组名称。
CVSS情報
N/A
脆弱性タイプ
N/A