exu@feditown.com to Selfhosted@lemmy.worldEnglish · 1 month agoCritical Keycloak Vulnerability (CVSS 9.1) - CVE-2026-18963access.redhat.comexternal-linkmessage-square3linkfedilinkarrow-up10arrow-down10file-text
arrow-up10arrow-down1external-linkCritical Keycloak Vulnerability (CVSS 9.1) - CVE-2026-18963access.redhat.comexu@feditown.com to Selfhosted@lemmy.worldEnglish · 1 month agomessage-square3linkfedilinkfile-text
Update your Keycloak For community, version 26.7.2 has the fix: https://www.keycloak.org/2026/08/keycloak-2672-released
minus-squareplateee@piefed.sociallinkfedilinkEnglisharrow-up0·1 month agoThis one is bad - unauthenticated user account take over. If you’re like me and only using it internally on a homelab, the risks are lessened, but if you expose keycloak to by the Internet - boy howdy
minus-squareiamthetot@piefed.calinkfedilinkEnglisharrow-up0·1 month agoOut of curiosity, what is the advantage of using something like this on LAN only?
minus-squarePossibly linux@lemmy.ziplinkfedilinkEnglisharrow-up0arrow-down1·1 month agoNot being impacted by security issues like these for one
This one is bad - unauthenticated user account take over.
If you’re like me and only using it internally on a homelab, the risks are lessened, but if you expose keycloak to by the Internet - boy howdy
Out of curiosity, what is the advantage of using something like this on LAN only?
Not being impacted by security issues like these for one