google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

PRP: Keycloak Admin Console Weak Credential Tester #500

Open lanced00m opened 3 weeks ago

lanced00m commented 3 weeks ago

Keycloak is one of the most used identity and access management frameworks in organizations. according to the document for at least the docker setup we have default credentials: https://www.keycloak.org/getting-started/getting-started-docker Furthermore, I would like to do more research to find additional default credentials.