OSV 1.4.0 · unreviewed · 修改于 2026-09-02 11:31
发布时间
2026-09-02 11:31
GitHub 审查时间
—
NVD 发布时间
2026-09-02 10:17
源文件
advisories/unreviewed/2026/09/GHSA-2w6p-j7xq-6p7v/GHSA-2w6p-j7xq-6p7v.json
A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.
该公告没有提供结构化的受影响软件包信息。