Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm29-6wx7-p874

Опубликовано: 03 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Keycloak insufficient session expiration

A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

Пакеты

Наименование

org.keycloak:keycloak-parent

maven
Затронутые версииВерсия исправления

< 14.0.0

14.0.0

EPSS

Процентиль: 16%
0.00052
Низкий

7.1 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 7.1
redhat
почти 5 лет назад

A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

CVSS3: 7.1
nvd
почти 4 года назад

A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

CVSS3: 7.1
debian
почти 4 года назад

A flaw was found in keycloak where keycloak may fail to logout user se ...

EPSS

Процентиль: 16%
0.00052
Низкий

7.1 High

CVSS3

Дефекты

CWE-613