Описание
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session.
This issue affects Symmetric Key Agreement Platform: before 26.03.
EPSS
Процентиль: 3%
0.00134
Низкий
3.8 Low
CVSS3
Дефекты
CWE-233
Связанные уязвимости
CVSS3: 3.8
github
3 месяца назад
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
EPSS
Процентиль: 3%
0.00134
Низкий
3.8 Low
CVSS3
Дефекты
CWE-233