Количество 4
Количество 4
CVE-2026-3911
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
CVE-2026-3911
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
CVE-2026-3911
A flaw was found in Keycloak. An authenticated user with the view-user ...
GHSA-xh32-c9wx-phrp
Keycloak: Information disclosure of disabled user attributes via administrative endpoint
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-3911 A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data. | CVSS3: 2.7 | 0% Низкий | 16 дней назад | |
CVE-2026-3911 A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data. | CVSS3: 2.7 | 0% Низкий | 16 дней назад | |
CVE-2026-3911 A flaw was found in Keycloak. An authenticated user with the view-user ... | CVSS3: 2.7 | 0% Низкий | 16 дней назад | |
GHSA-xh32-c9wx-phrp Keycloak: Information disclosure of disabled user attributes via administrative endpoint | CVSS3: 2.7 | 0% Низкий | 16 дней назад |
Уязвимостей на страницу