Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc72-gfvw-76h7

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Keycloak Oauth Implementation Error

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

Пакеты

Наименование

org.keycloak:keycloak-parent

maven
Затронутые версииВерсия исправления

< 3.3.0.Final

3.3.0.Final

EPSS

Процентиль: 78%
0.01887
Низкий

7.2 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 3.1
redhat
почти 9 лет назад

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

CVSS3: 7.2
nvd
почти 9 лет назад

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

CVSS3: 7.2
debian
почти 9 лет назад

It was found that Keycloak oauth would permit an authenticated resourc ...

EPSS

Процентиль: 78%
0.01887
Низкий

7.2 High

CVSS3

Дефекты

CWE-287