Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v436-q368-hvgg

Опубликовано: 12 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Keycloak has lack of validation of access token on client registrations endpoint

When a service account with the create-client or manage-clients role can use the client-registration endpoints to create/manage clients with an access token.

If the access token is leaked, there is an option to revoke the specific token. However, the check is not performed in client-registration endpoints.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

<= 20.0.2

20.0.3

EPSS

Процентиль: 27%
0.00097
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284
CWE-863

Связанные уязвимости

CVSS3: 3.8
redhat
больше 3 лет назад

A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

CVSS3: 3.8
nvd
около 3 лет назад

A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

CVSS3: 3.8
debian
около 3 лет назад

A flaw was found in Keycloak, where it did not properly check client t ...

EPSS

Процентиль: 27%
0.00097
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284
CWE-863