Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3868

Опубликовано: 24 апр. 2019
Источник: debian
EPSS Низкий

Описание

Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 52%
0.00291
Низкий

Связанные уязвимости

CVSS3: 3.8
redhat
почти 7 лет назад

Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.

CVSS3: 3.8
nvd
почти 7 лет назад

Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.

CVSS3: 3.8
github
почти 7 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Keycloak

EPSS

Процентиль: 52%
0.00291
Низкий