Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-3911

Опубликовано: 11 мар. 2026
Источник: nvd
CVSS3: 2.7
EPSS Низкий

Описание

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:26.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:26.4.11:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00332
Низкий

2.7 Low

CVSS3

Дефекты

CWE-359
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 2.7
redhat
5 месяцев назад

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.

CVSS3: 2.7
debian
5 месяцев назад

A flaw was found in Keycloak. An authenticated user with the view-user ...

CVSS3: 2.7
github
5 месяцев назад

Keycloak: Information disclosure of disabled user attributes via administrative endpoint

EPSS

Процентиль: 26%
0.00332
Низкий

2.7 Low

CVSS3

Дефекты

CWE-359
NVD-CWE-noinfo