Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfxv-6gx8-3fm6

Опубликовано: 29 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

EPSS

Процентиль: 22%
0.00292
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 6.5
redhat
20 дней назад

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

CVSS3: 6.5
nvd
19 дней назад

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

CVSS3: 6.5
debian
19 дней назад

A flaw was found in the client policy enforcement mechanism of Keycloa ...

EPSS

Процентиль: 22%
0.00292
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285