Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hw58-3793-42gg

Опубликовано: 30 апр. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Keycloak hostname verification

A flaw was found in Keycloak. By setting a verification policy to 'ANY', the trust store certificate verification is skipped, which is unintended.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 26.2.2

26.2.2

EPSS

Процентиль: 2%
0.00015
Низкий

8.2 High

CVSS3

Дефекты

CWE-297

Связанные уязвимости

CVSS3: 8.2
redhat
5 месяцев назад

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

CVSS3: 8.2
nvd
5 месяцев назад

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

CVSS3: 8.2
debian
5 месяцев назад

A flaw was found in Keycloak. By setting a verification policy to 'ALL ...

EPSS

Процентиль: 2%
0.00015
Низкий

8.2 High

CVSS3

Дефекты

CWE-297