Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc72-gfvw-76h7

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Keycloak Oauth Implementation Error

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

Пакеты

Наименование

org.keycloak:keycloak-parent

maven
Затронутые версииВерсия исправления

< 3.3.0.Final

3.3.0.Final

EPSS

Процентиль: 68%
0.00571
Низкий

7.2 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 3.1
redhat
больше 8 лет назад

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

CVSS3: 7.2
nvd
больше 8 лет назад

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

CVSS3: 7.2
debian
больше 8 лет назад

It was found that Keycloak oauth would permit an authenticated resourc ...

EPSS

Процентиль: 68%
0.00571
Низкий

7.2 High

CVSS3

Дефекты

CWE-287