Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mw35-24gh-f82w

Опубликовано: 15 нояб. 2017
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

keycloak-connect and keycloak-js improperly handle invalid tokens

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

Пакеты

Наименование

keycloak-connect

npm
Затронутые версииВерсия исправления

>= 2.5.0, < 3.1.0

3.1.0

Наименование

keycloak-js

npm
Затронутые версииВерсия исправления

>= 2.5.0, < 3.1.0

3.1.0

EPSS

Процентиль: 82%
0.01726
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-253

Связанные уязвимости

CVSS3: 8.1
redhat
почти 9 лет назад

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

CVSS3: 9.8
nvd
больше 8 лет назад

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

CVSS3: 9.8
debian
больше 8 лет назад

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handl ...

EPSS

Процентиль: 82%
0.01726
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-253