Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q929-g23j-2rc7

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain privileged API access. The primary impact includes unauthorized information disclosure and potential integrity compromise.

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain privileged API access. The primary impact includes unauthorized information disclosure and potential integrity compromise.

EPSS

Процентиль: 18%
0.00267
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 месяца назад

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain privileged API access. The primary impact includes unauthorized information disclosure and potential integrity compromise.

CVSS3: 6.5
nvd
около 1 месяца назад

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain privileged API access. The primary impact includes unauthorized information disclosure and potential integrity compromise.

CVSS3: 6.5
debian
около 1 месяца назад

A flaw was found in Keycloak's client registration service. A remote a ...

EPSS

Процентиль: 18%
0.00267
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-613