CVE-2024-3656
by @h4x0r-dz
31
Keycloak admin API allows low privilege users to use administrative functions
About this project
Keycloak send HTTP requset to the vulnerable endpoint : in the parameter connectionUrl put Your external host and send the Requset, then You will receive the DNS interaction you can apply the same thing with getUnmanagedAttributes and getProviders. reference: https://github.com/keycloak/keycloak/commit/d9f0c84b797525eac55914db5f81a8133ef5f9b1 https://github.com/advisories/GHSA-2cww-fgmg-4jqc
From the project README on GitHub
- Stars
- 31
- Forks
- 10
- Last push
- 12 Oct 2024
Add this badge to your README
Show that your project is listed on Made in Algeria.
[](https://www.madeinalgeria.dev/projects/cve-2024-3656)