Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95m6-mjh3-58gm

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Improper Authentication in org.keycloak:keycloak-core

It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 2.3.0

2.3.0

EPSS

Процентиль: 37%
0.00157
Низкий

8.1 High

CVSS3

Дефекты

CWE-287
CWE-384

Связанные уязвимости

CVSS3: 3.7
redhat
около 9 лет назад

It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.

CVSS3: 3.7
nvd
больше 7 лет назад

It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.

CVSS3: 3.7
debian
больше 7 лет назад

It was found that the keycloak before 2.3.0 did not implement authenti ...

EPSS

Процентиль: 37%
0.00157
Низкий

8.1 High

CVSS3

Дефекты

CWE-287
CWE-384