Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6qj-3mpp-57v8

Опубликовано: 20 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.4

Описание

Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 26.6.3

26.6.3

EPSS

Процентиль: 24%
0.00312
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.4
redhat
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

CVSS3: 6.4
nvd
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

CVSS3: 6.4
debian
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is ...

EPSS

Процентиль: 24%
0.00312
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-639