Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcf4-9g97-7cpf

Опубликовано: 04 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.

EPSS

Процентиль: 6%
0.0016
Низкий

3.7 Low

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 3.7
redhat
17 дней назад

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.

CVSS3: 3.7
nvd
13 дней назад

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.

CVSS3: 3.7
debian
13 дней назад

A flaw was found in the backchannel logout endpoint of the keycloak-se ...

EPSS

Процентиль: 6%
0.0016
Низкий

3.7 Low

CVSS3

Дефекты

CWE-347