git: 2666126bb63f - main - net/keycloak: document multiple vulnerabilities

From: Robert Clausecker <fuz_at_FreeBSD.org>
Date: Wed, 27 Nov 2024 12:02:04 UTC
The branch main has been updated by fuz:

URL: https://cgit.FreeBSD.org/ports/commit/?id=2666126bb63f63f6b18453b96eb08a746ca2bf28

commit 2666126bb63f63f6b18453b96eb08a746ca2bf28
Author:     Matthias Wolf <freebsd@rheinwolf.de>
AuthorDate: 2024-11-26 12:23:17 +0000
Commit:     Robert Clausecker <fuz@FreeBSD.org>
CommitDate: 2024-11-27 11:57:29 +0000

    net/keycloak: document multiple vulnerabilities
    
    Security:       CVE-2024-9666 CVE-2024-10039 CVE-2024-10270
    Security:       CVE-2024-10451 CVE-2024-10492
    PR:             282983
---
 security/vuxml/vuln/2024.xml | 36 ++++++++++++++++++++++++++++++++++++
 1 file changed, 36 insertions(+)

diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml
index 40b332a1f6f8..15a3097857d7 100644
--- a/security/vuxml/vuln/2024.xml
+++ b/security/vuxml/vuln/2024.xml
@@ -1,3 +1,39 @@
+  <vuln vid="7d7a28cd-7f5a-450a-852f-c49aaab3fa7e">
+    <topic>keycloak -- Multiple security fixes</topic>
+    <affects>
+      <package>
+	<name>keycloak</name>
+	<range><lt>26.0.6</lt></range>
+      </package>
+    </affects>
+    <description>
+      <body xmlns="http://www.w3.org/1999/xhtml">
+	<p>Keycloak reports:</p>
+	<blockquote cite="https://www.keycloak.org/2024/11/keycloak-2606-released.html">
+	  <p>This update includes 5 security fixes:</p>
+	  <ul>
+	    <li>CVE-2024-10451: Sensitive Data Exposure in Keycloak Build Process</li>
+	    <li>CVE-2024-10270: Potential Denial of Service</li>
+	    <li>CVE-2024-10492: Keycloak path trasversal</li>
+	    <li>CVE-2024-9666: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability</li>
+	    <li>CVE-2024-10039: Bypassing mTLS validation</li>
+	  </ul>
+	</blockquote>
+      </body>
+    </description>
+    <references>
+      <cvename>CVE-2021-9666</cvename>
+      <cvename>CVE-2021-10039</cvename>
+      <cvename>CVE-2021-10270</cvename>
+      <cvename>CVE-2021-10451</cvename>
+      <cvename>CVE-2021-10492</cvename>
+    </references>
+    <dates>
+      <discovery>2024-11-22</discovery>
+      <entry>2024-11-25</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="2263ea04-ac81-11ef-998c-2cf05da270f3">
     <topic>Gitlab -- vulnerabilities</topic>
     <affects>