Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r934-w73g-v4p8

Опубликовано: 29 апр. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Duplicate Advisory: Keycloak hostname verification

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-hw58-3793-42gg. This link is maintained to preserve external references.

Original Description

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 26.2.2

26.2.2

8.2 High

CVSS3

Дефекты

CWE-297

8.2 High

CVSS3

Дефекты

CWE-297