Логотип exploitDog
bind:CVE-2017-12160
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-12160

Количество 4

Количество 4

redhat логотип

CVE-2017-12160

больше 8 лет назад

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2017-12160

больше 8 лет назад

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

CVSS3: 7.2
EPSS: Низкий
debian логотип

CVE-2017-12160

больше 8 лет назад

It was found that Keycloak oauth would permit an authenticated resourc ...

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-qc72-gfvw-76h7

больше 3 лет назад

Keycloak Oauth Implementation Error

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

CVSS3: 3.1
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.

CVSS3: 7.2
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resourc ...

CVSS3: 7.2
1%
Низкий
больше 8 лет назад
github логотип
GHSA-qc72-gfvw-76h7

Keycloak Oauth Implementation Error

CVSS3: 7.2
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу