Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6gv-3r3v-gwgj

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

keycloak-core vulnerable to timing attacks against JWS token verification

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 2.5.1

2.5.1

EPSS

Процентиль: 71%
0.00671
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.7
redhat
почти 9 лет назад

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.

CVSS3: 5.9
nvd
почти 8 лет назад

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.

CVSS3: 5.9
debian
почти 8 лет назад

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC ve ...

EPSS

Процентиль: 71%
0.00671
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200