PT-2017-5884 · Red Hat · Jboss Keycloak+1

Publicado

2017-10-18

·

Atualizado

2022-05-17

·

CVE-2014-3709

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: JBoss KeyCloak versions prior to 1.0.3.Final
Description: The issue allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging the lack of CSRF protection in the org.keycloak.services.resources.SocialResource.callback method.
Recommendations: For versions prior to 1.0.3.Final, update to version 1.0.3.Final or later to resolve the issue. As a temporary workaround, consider implementing additional CSRF protection measures to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3709
GHSA-XR6Q-QQX7-553G

Produtos afetados

Jboss Keycloak
Keycloak