Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10157

Опубликовано: 12 июн. 2019
Источник: debian
EPSS Низкий

Описание

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 4%
0.00019
Низкий

Связанные уязвимости

CVSS3: 4.7
redhat
больше 6 лет назад

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

CVSS3: 4.7
nvd
больше 6 лет назад

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

CVSS3: 5.5
github
больше 6 лет назад

Forced Logout in keycloak-connect

EPSS

Процентиль: 4%
0.00019
Низкий