安全速报自动同步 · 保留上游原文

【高危】keycloak-services:信息泄露风险(GHSA-794g-x443-36f7)

S
KHack 安全情报
2026/7/3 发布 · 2 阅读

安全情报快照 · 风险级别:高危 · CVSS:7.7 · CVE-2026-2092 · GHSA-794g-x443-36f7

先看结论

keycloak-services存在信息泄露风险,<= 26.2.5 受影响。上游暂未提供明确修复版本。

影响范围

生态 组件 受影响版本 首个修复版本
maven org.keycloak:keycloak-services <= 26.2.5
maven org.keycloak:keycloak-services >= 26.3.0, <= 26.4.7
maven org.keycloak:keycloak-services >= 26.5.0, < 26.5.5

处置建议

上游公告暂未给出明确修复版本。请持续关注项目维护者发布的补丁,并结合受影响版本范围排查资产。

上游技术详情(原文)

Keycloak's SAML broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response, injecting an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.

来源与许可

本页自动同步 GitHub Advisory Database 的公开数据,并保留上游原文供核验;不宣称原创分析。数据许可:CC-BY-4.0。

评论

还没有评论,来说两句。