Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6mm-q862-j366

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Input Validation in Keycloak

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 11.0.0

11.0.0

Наименование

org.keycloak:keycloak-common

maven
Затронутые версииВерсия исправления

< 11.0.0

11.0.0

EPSS

Процентиль: 84%
0.02152
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
redhat
больше 5 лет назад

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.

CVSS3: 8.8
nvd
больше 5 лет назад

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.

CVSS3: 8.8
debian
больше 5 лет назад

A flaw was found in Keycloak before version 11.0.0, where the code bas ...

EPSS

Процентиль: 84%
0.02152
Низкий

8.8 High

CVSS3

Дефекты

CWE-20