Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68hw-vfh7-xvg8

Опубликовано: 13 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Forced Logout in keycloak-connect

Versions of keycloak-connect prior to 4.4.0 are vulnerable to Forced Logout. The package fails to validate JWT signatures on the /k_logout route, allowing attackers to logout users and craft malicious JWTs with NBF values that prevent user access indefinitely.

Recommendation

Upgrade to version 4.4.0 or later.

Пакеты

Наименование

keycloak-connect

npm
Затронутые версииВерсия исправления

< 4.8.3

4.8.3

EPSS

Процентиль: 4%
0.00019
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-287
CWE-345

Связанные уязвимости

CVSS3: 4.7
redhat
больше 6 лет назад

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

CVSS3: 4.7
nvd
больше 6 лет назад

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

CVSS3: 4.7
debian
больше 6 лет назад

It was found that Keycloak's Node.js adapter before version 4.8.3 did ...

EPSS

Процентиль: 4%
0.00019
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-287
CWE-345