→ كل المشاريع

CVE-2024-3656

بواسطة @h4x0r-dz

31

Keycloak admin API allows low privilege users to use administrative functions

عن هذا المشروع

Keycloak send HTTP requset to the vulnerable endpoint : in the parameter connectionUrl put Your external host and send the Requset, then You will receive the DNS interaction you can apply the same thing with getUnmanagedAttributes and getProviders. reference: https://github.com/keycloak/keycloak/commit/d9f0c84b797525eac55914db5f81a8133ef5f9b1 https://github.com/advisories/GHSA-2cww-fgmg-4jqc

من ملف README الخاص بالمشروع على GitHub

النجوم
31
التفريعات
10
آخر تحديث
12/10/2024

أضف هذه الشارة إلى ملف README

أظهر أن مشروعك مُدرج على «صُنع في الجزائر».

Made in Algeria
[![Made in Algeria](https://www.madeinalgeria.dev/badge/cve-2024-3656.svg)](https://www.madeinalgeria.dev/projects/cve-2024-3656)

مشاريع ذات صلة