Описание
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
EPSS
Процентиль: 6%
0.00023
Низкий
2.7 Low
CVSS3
Дефекты
CWE-266
Связанные уязвимости
CVSS3: 2.7
debian
6 дней назад
A flaw was found in Keycloak Admin API. This vulnerability allows an a ...
CVSS3: 2.7
github
6 дней назад
Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
EPSS
Процентиль: 6%
0.00023
Низкий
2.7 Low
CVSS3
Дефекты
CWE-266