Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fmw-85qm-h22p

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Keycloak CSRF Vulnerability

It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.

Пакеты

Наименование

org.keycloak:keycloak-parent

maven
Затронутые версииВерсия исправления

< 3.4.0

3.4.0

EPSS

Процентиль: 69%
0.00588
Низкий

7.5 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5.4
redhat
больше 8 лет назад

It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.

CVSS3: 7.5
nvd
больше 8 лет назад

It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.

CVSS3: 7.5
debian
больше 8 лет назад

It was found that the cookie used for CSRF prevention in Keycloak was ...

EPSS

Процентиль: 69%
0.00588
Низкий

7.5 High

CVSS3

Дефекты

CWE-613