漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution
Vulnerability Description
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
Keycloak 输入验证错误漏洞
Vulnerability Description
Keycloak是Keycloak组织开源的一种身份和访问管理解决方案。 Keycloak存在输入验证错误漏洞,该漏洞源于SAML协议实现处理HTTP-Redirect绑定的认证请求时存在缺陷,如果客户端配置了通配符重定向URL,攻击者可构造包含恶意参数的请求,导致合法响应被附加到攻击者参数上,可能使服务提供商处理攻击者数据,导致用户登录到错误账户。
CVSS Information
N/A
Vulnerability Type
N/A