VDB
BDU%3A2024-05695
BDU%3A2024-05695
PUBLISHED
CVSS 5.400000095367432 MEDIUM
Уязвимость компонента Client Registration Handler программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat build of Keycloak 22 | 22-13 |
| Red Hat | RHEL-8 based Middleware Containers | 7.6-46 |
| Red Hat | Red Hat build of Keycloak 22.0.10 | |
| Red Hat | Red Hat build of Keycloak 22 | 22-16 |
| Red Hat | Red Hat build of Keycloak 22 | 22.0.10-1 |
| Red Hat | RHSSO 7.6.8 | |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 9 | 0:18.0.13-1.redhat_00001.1.el9sso |
| 23.0.0, 22.0.0 | ||
| Red Hat Inc. | Red Hat Single Sign-On, Red Hat Build of Keycloak | |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 7 | 0:18.0.13-1.redhat_00001.1.el7sso |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 8 | 0:18.0.13-1.redhat_00001.1.el8sso |
Timeline
- Apr 25, 2024 CVE Published
- Jul 24, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- May 31, 2026 Distribution Patch
- May 31, 2026 Security Advisory
- May 31, 2026 Distribution Patch
- May 31, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:1860 url
- https://access.redhat.com/errata/RHSA-2024:1862 url
- RHSA-2024:1864 vendor-advisory
- RHSA-2024:1868 vendor-advisory
- https://access.redhat.com/errata/RHSA-2024:1861 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2253116 url
- https://access.redhat.com/security/cve/CVE-2023-6544 advisory
- https://access.redhat.com/errata/RHSA-2024:1866 url
- https://access.redhat.com/errata/RHSA-2024:1867 url
- https://vuldb.com/?id.260949 url