Skip to content

Commit e5cc475

Browse files
1 parent c88760a commit e5cc475

2 files changed

Lines changed: 5 additions & 5 deletions

File tree

advisories/github-reviewed/2026/03/GHSA-22rm-wp4x-v5cx/GHSA-22rm-wp4x-v5cx.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-22rm-wp4x-v5cx",
4-
"modified": "2026-03-27T20:03:17Z",
4+
"modified": "2026-04-13T18:35:11Z",
55
"published": "2026-03-26T09:30:28Z",
66
"aliases": [
77
"CVE-2026-4874"
@@ -28,7 +28,7 @@
2828
"introduced": "0"
2929
},
3030
{
31-
"last_affected": "26.5.6"
31+
"last_affected": "26.6.0"
3232
}
3333
]
3434
}

advisories/github-reviewed/2026/03/GHSA-4pgc-gfrr-wcmg/GHSA-4pgc-gfrr-wcmg.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-4pgc-gfrr-wcmg",
4-
"modified": "2026-03-26T19:25:57Z",
4+
"modified": "2026-04-13T18:36:28Z",
55
"published": "2026-03-23T09:30:30Z",
66
"aliases": [
77
"CVE-2026-4628"
88
],
9-
"summary": "Keycloak has Improper Access Control allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false",
9+
"summary": "Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false",
1010
"details": "A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs due to incomplete enforcement of access control checks on PUT operations to the resource_set endpoint. This issue enables unauthorized modification of protected resources, impacting data integrity.",
1111
"severity": [
1212
{
@@ -28,7 +28,7 @@
2828
"introduced": "0"
2929
},
3030
{
31-
"last_affected": "26.5.6"
31+
"last_affected": "26.6.0"
3232
}
3333
]
3434
}

0 commit comments

Comments
 (0)