Keycloak
26.5.1Security2026년 1월 14일
Keycloak 26.5.1은 보안 문제와 동작 오류를 바로잡고 관리 및 HTTP 응답 관련 동작을 조정한 릴리스입니다. `Organization` 기능을 사용한다면 사용자 및 비밀번호 양식에 계정 이름이 자동으로 표시되는 문제와 관련됩니다.
영향 확인 (1)
security
Organization기능의 계정 이름 자동 노출 문제 수정Organization기능을 사용하는 경우에 적용됩니다.Organization기능이 사용자 및 비밀번호 양식에 계정 이름을 자동으로 표시하고 채우던 보안 문제를 수정했습니다.
그 외 기록된 변경 13건 전체fixes 10 · value changes 2 · additions 1
fixes (10)
- 403 Forbidden when assigning realm-management client roles despite FGAP disabled (regression in 26.4.0+)
- Create Realm button is missing when user has create-realm role
- Admin UI: slow response time listing second user page
- Bug in JWTClientAuthenticator and JWTClientSecretAuthenticator causes NPE
- Enable visibility of Role Mapping tab for users with view-users role
- Failed upgrade to 26.4.7 - sql generated for manual database upgrade contains invalid statements
- Realm-level admininistrators can no longer use Admin Console since 26.3.0 (UI fails to render)
- Failure when decrypting SAML Response since 26.5.0
- Upgrade to 26.5.0 failing due to FK_ORG_INVITATION_ORG constraint
- UI Bug: WebAuthn passkey list is broken in keycloak v2 theme
value changes (2)
- x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses
- Performance improvement: Missing indexes on BROKER_LINK table columns
additions (1)
- Allow full managing of realms from master realm without global admin role
Keycloak 스택에 추가
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.