Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf65-pwfc-rxcm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks. Versions shipped with Red Hat Mobile Aplication Platform 4 are believed to be vulnerable.

The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks. Versions shipped with Red Hat Mobile Aplication Platform 4 are believed to be vulnerable.

EPSS

Процентиль: 36%
0.00155
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.3
redhat
около 5 лет назад

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0

CVSS3: 6.1
nvd
около 5 лет назад

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0

CVSS3: 6.1
debian
около 5 лет назад

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint ...

EPSS

Процентиль: 36%
0.00155
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-601