Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7474

Опубликовано: 08 мая 2017
Источник: redhat
CVSS3: 8.1

Описание

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

It was found that the Keycloak Node.js adapter did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7keycloak-connectAffected
Red Hat Single Sign-On 7.1FixedRHSA-2017:120308.05.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-253
https://bugzilla.redhat.com/show_bug.cgi?id=1445271keycloak-connect: auth token validity check ignored

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

CVSS3: 9.8
debian
больше 8 лет назад

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handl ...

CVSS3: 9.8
github
около 8 лет назад

keycloak-connect and keycloak-js improperly handle invalid tokens

8.1 High

CVSS3