PT-2017-12374 · Red Hat · Keycloak

Publicado

2017-10-26

·

Atualizado

2026-05-18

·

CVE-2017-12159

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw was found in Keycloak's CSRF prevention mechanism, where the cookie used was not unique to each session. This could allow an attacker to gain access to an authenticated user's session, potentially leading to information disclosure or further attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CLEANSTART-2026-FA60324
CLEANSTART-2026-GX01236
CLEANSTART-2026-KC06018
CLEANSTART-2026-PO27799
CLEANSTART-2026-SG80587
CVE-2017-12159
GHSA-7FMW-85QM-H22P
RHSA-2017:2904
RHSA-2017:2905

Produtos afetados

Keycloak