Vulnerabilities
Vulnerable Software
Redhat:  >> Keycloak  >> 24.0.8  Security Vulnerabilities
A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
CVSS Score
4.9
EPSS Score
0.0
Published
2026-02-27
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.
CVSS Score
7.1
EPSS Score
0.017
Published
2024-09-09


Contact Us

Shodan ® - All rights reserved