Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh32-c9wx-phrp

Опубликовано: 11 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 2.7

Описание

Keycloak: Information disclosure of disabled user attributes via administrative endpoint

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 26.5.5

Отсутствует

EPSS

Процентиль: 1%
0.00011
Низкий

2.7 Low

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 2.7
redhat
16 дней назад

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS3: 2.7
nvd
16 дней назад

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS3: 2.7
debian
16 дней назад

A flaw was found in Keycloak. An authenticated user with the view-user ...

EPSS

Процентиль: 1%
0.00011
Низкий

2.7 Low

CVSS3

Дефекты

CWE-359