Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79qw-g39g-mfxc

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

EPSS

Процентиль: 23%
0.00308
Низкий

8.1 High

CVSS3

Дефекты

CWE-1025

Связанные уязвимости

CVSS3: 8.1
redhat
2 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

CVSS3: 8.1
nvd
около 1 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

CVSS3: 8.1
debian
около 1 месяца назад

A flaw was found in Keycloak Policy Enforcer. This vulnerability allow ...

EPSS

Процентиль: 23%
0.00308
Низкий

8.1 High

CVSS3

Дефекты

CWE-1025