Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10157

Опубликовано: 12 июн. 2019
Источник: debian
EPSS Низкий

Описание

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 11%
0.00208
Низкий

Связанные уязвимости

CVSS3: 4.7
redhat
около 7 лет назад

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

CVSS3: 4.7
nvd
около 7 лет назад

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

CVSS3: 5.5
github
около 7 лет назад

Forced Logout in keycloak-connect

EPSS

Процентиль: 11%
0.00208
Низкий