Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23qf-mx2g-p3gq

Опубликовано: 23 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.5

Описание

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.

EPSS

Процентиль: 27%
0.00093
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 4.5
nvd
почти 2 года назад

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.

EPSS

Процентиль: 27%
0.00093
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-201