Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjf4-6f34-w64q

Опубликовано: 19 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.8

Описание

Keycloak: Missing Check on Disabled Client for Docker Registry Protocol

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access. As a result, previously valid credentials can still be used to obtain authentication tokens. This weakens administrative controls and could allow unintended access to container registry resources.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 26.5.3

Отсутствует

EPSS

Процентиль: 13%
0.00042
Низкий

3.8 Low

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 3.8
redhat
около 1 месяца назад

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access. As a result, previously valid credentials can still be used to obtain authentication tokens. This weakens administrative controls and could allow unintended access to container registry resources.

CVSS3: 3.8
nvd
около 1 месяца назад

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access. As a result, previously valid credentials can still be used to obtain authentication tokens. This weakens administrative controls and could allow unintended access to container registry resources.

CVSS3: 3.8
debian
около 1 месяца назад

A flaw was identified in the Docker v2 authentication endpoint of Keyc ...

EPSS

Процентиль: 13%
0.00042
Низкий

3.8 Low

CVSS3

Дефекты

CWE-285