Описание
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
EPSS
Процентиль: 29%
0.00364
Низкий
2.7 Low
CVSS3
Дефекты
CWE-266
Связанные уязвимости
CVSS3: 2.7
redhat
7 месяцев назад
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
CVSS3: 2.7
debian
7 месяцев назад
A flaw was found in Keycloak Admin API. This vulnerability allows an a ...
CVSS3: 2.7
github
7 месяцев назад
Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
EPSS
Процентиль: 29%
0.00364
Низкий
2.7 Low
CVSS3
Дефекты
CWE-266