Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rvjg-gxwx-j5gf

Опубликовано: 28 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

OIDC Logout redirect in keycloak

A flaw was found in keycloak. The OIDC logout endpoint does not have CSRF protection. The highest threat from this vulnerability is to system availability.

Пакеты

Наименование

org.keycloak:keycloak-oidc-client-adapter-pom

maven
Затронутые версииВерсия исправления

< 18.0.0

18.0.0

EPSS

Процентиль: 4%
0.0002
Низкий

3.3 Low

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 3.3
redhat
почти 5 лет назад

A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.

CVSS3: 3.3
nvd
почти 5 лет назад

A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.

CVSS3: 3.3
debian
почти 5 лет назад

A vulnerability was found in keycloak in the way that the OIDC logout ...

EPSS

Процентиль: 4%
0.0002
Низкий

3.3 Low

CVSS3

Дефекты

CWE-601