Описание
An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.
Ссылки
- Release Notes
- ExploitThird Party Advisory
- Release Notes
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.8 (исключая)
cpe:2.3:a:michaelkelly:duouniversalkeycloakauthenticator:*:*:*:*:*:keycloak:*:*
EPSS
Процентиль: 29%
0.00103
Низкий
4.5 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-201
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 4.5
github
около 2 лет назад
An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.
EPSS
Процентиль: 29%
0.00103
Низкий
4.5 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-201
NVD-CWE-noinfo