Skip to content

Commit acc7dc7

Browse files
committed
1 parent a1ec1ee commit acc7dc7

1 file changed

Lines changed: 7 additions & 10 deletions

File tree

advisories/github-reviewed/2026/03/GHSA-rhgq-f8x5-j2jc/GHSA-rhgq-f8x5-j2jc.json

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-rhgq-f8x5-j2jc",
4-
"modified": "2026-04-13T17:55:01Z",
4+
"modified": "2026-04-13T17:55:02Z",
55
"published": "2026-03-23T12:30:30Z",
66
"aliases": [
77
"CVE-2026-4633"
88
],
9-
"summary": "Keycloak's identity-first login flow exposes user information",
9+
"summary": "Keycloak's identity-first login flow exposes user information",
1010
"details": "A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.",
1111
"severity": [
1212
{
@@ -25,17 +25,14 @@
2525
"type": "ECOSYSTEM",
2626
"events": [
2727
{
28-
"introduced": "26.5.0"
28+
"introduced": "0"
2929
},
3030
{
31-
"fixed": "26.6.0"
31+
"fixed": "26.4.12"
3232
}
3333
]
3434
}
35-
],
36-
"database_specific": {
37-
"last_known_affected_version_range": "<= 26.5.6"
38-
}
35+
]
3936
},
4037
{
4138
"package": {
@@ -47,10 +44,10 @@
4744
"type": "ECOSYSTEM",
4845
"events": [
4946
{
50-
"introduced": "0"
47+
"introduced": "26.5.0"
5148
},
5249
{
53-
"last_affected": "26.4.7"
50+
"fixed": "26.6.1"
5451
}
5552
]
5653
}

0 commit comments

Comments
 (0)