Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-35509

Опубликовано: 23 авг. 2022
Источник: debian
EPSS Низкий

Описание

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 25%
0.00087
Низкий

Связанные уязвимости

CVSS3: 4.2
redhat
около 5 лет назад

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 5.4
nvd
больше 3 лет назад

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 5.4
github
больше 3 лет назад

Keycloak vulnerable to Improper Certificate Validation

EPSS

Процентиль: 25%
0.00087
Низкий