Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqjh-8322-vgrv

Опубликовано: 28 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Keycloak Generates an Error Message Containing Sensitive Information

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 26.4.7

Отсутствует

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 26.5.0, < 26.6.3

26.6.3

EPSS

Процентиль: 25%
0.00331
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 5.3
redhat
2 месяца назад

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.

CVSS3: 5.3
nvd
2 месяца назад

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.

CVSS3: 5.3
debian
2 месяца назад

A flaw was found in Keycloak. A remote, unauthenticated attacker can e ...

EPSS

Процентиль: 25%
0.00331
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-209