Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7474

Опубликовано: 12 мая 2017
Источник: debian
EPSS Низкий

Описание

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 82%
0.01726
Низкий

Связанные уязвимости

CVSS3: 8.1
redhat
почти 9 лет назад

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

CVSS3: 9.8
nvd
больше 8 лет назад

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

CVSS3: 9.8
github
около 8 лет назад

keycloak-connect and keycloak-js improperly handle invalid tokens

EPSS

Процентиль: 82%
0.01726
Низкий