Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3461

Опубликовано: 22 мар. 2021
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat Integration Camel K 1keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat support for Spring BootkeycloakNot affected
Red Hat Single Sign-On 7.4.7FixedRHSA-2021:207020.05.2021
Red Hat Single Sign-On 7.4 for RHEL 6rh-sso7-keycloakFixedRHSA-2021:206320.05.2021
Red Hat Single Sign-On 7.4 for RHEL 7rh-sso7-keycloakFixedRHSA-2021:206420.05.2021
Red Hat Single Sign-On 7.4 for RHEL 8rh-sso7-keycloakFixedRHSA-2021:206520.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=1941565keycloak: Backchannel logout not working when Principal Type is set to Attribute Name for external SAML IDP

EPSS

Процентиль: 16%
0.00052
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
почти 4 года назад

A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

CVSS3: 7.1
debian
почти 4 года назад

A flaw was found in keycloak where keycloak may fail to logout user se ...

CVSS3: 7.1
github
почти 4 года назад

Keycloak insufficient session expiration

EPSS

Процентиль: 16%
0.00052
Низкий

7.1 High

CVSS3