CVE-2024-3656
بواسطة @h4x0r-dz
31
Keycloak admin API allows low privilege users to use administrative functions
عن هذا المشروع
Keycloak send HTTP requset to the vulnerable endpoint : in the parameter connectionUrl put Your external host and send the Requset, then You will receive the DNS interaction you can apply the same thing with getUnmanagedAttributes and getProviders. reference: https://github.com/keycloak/keycloak/commit/d9f0c84b797525eac55914db5f81a8133ef5f9b1 https://github.com/advisories/GHSA-2cww-fgmg-4jqc
من ملف README الخاص بالمشروع على GitHub
- النجوم
- 31
- التفريعات
- 10
- آخر تحديث
- 12/10/2024
أضف هذه الشارة إلى ملف README
أظهر أن مشروعك مُدرج على «صُنع في الجزائر».
[](https://www.madeinalgeria.dev/projects/cve-2024-3656)