Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rpj2-w6fr-79hc

Опубликовано: 24 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Keycloak vulnerable to Improper Certificate Validation

keycloak accepts an expired certificate by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

This issue was partially fixed in version 13.0.1 and more completely fixed in version 14.0.0.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 14.0.0

14.0.0

EPSS

Процентиль: 25%
0.00087
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-20
CWE-295

Связанные уязвимости

CVSS3: 4.2
redhat
около 5 лет назад

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 5.4
nvd
больше 3 лет назад

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 5.4
debian
больше 3 лет назад

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An ...

EPSS

Процентиль: 25%
0.00087
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-20
CWE-295