RATATOSKRATATOSK
로그인

Keycloak

26.5.1Security
2026년 1월 14일

CHECK 1OTHER 13

Keycloak 26.5.1은 보안 문제와 동작 오류를 바로잡고 관리 및 HTTP 응답 관련 동작을 조정한 릴리스입니다. `Organization` 기능을 사용한다면 사용자 및 비밀번호 양식에 계정 이름이 자동으로 표시되는 문제와 관련됩니다.

영향 확인 (1)

  • securityOrganization 기능의 계정 이름 자동 노출 문제 수정

    Organization 기능을 사용하는 경우에 적용됩니다.

    Organization 기능이 사용자 및 비밀번호 양식에 계정 이름을 자동으로 표시하고 채우던 보안 문제를 수정했습니다.

그 외 기록된 변경 13건 전체fixes 10 · value changes 2 · additions 1

fixes (10)

  • 403 Forbidden when assigning realm-management client roles despite FGAP disabled (regression in 26.4.0+)
  • Create Realm button is missing when user has create-realm role
  • Admin UI: slow response time listing second user page
  • Bug in JWTClientAuthenticator and JWTClientSecretAuthenticator causes NPE
  • Enable visibility of Role Mapping tab for users with view-users role
  • Failed upgrade to 26.4.7 - sql generated for manual database upgrade contains invalid statements
  • Realm-level admininistrators can no longer use Admin Console since 26.3.0 (UI fails to render)
  • Failure when decrypting SAML Response since 26.5.0
  • Upgrade to 26.5.0 failing due to FK_ORG_INVITATION_ORG constraint
  • UI Bug: WebAuthn passkey list is broken in keycloak v2 theme

value changes (2)

  • x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses
  • Performance improvement: Missing indexes on BROKER_LINK table columns

additions (1)

  • Allow full managing of realms from master realm without global admin role
Keycloak 스택에 추가

조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.

스택에 추가