PT-2018-7116 · Red Hat · Red Hat Keycloak+1
Richard Kettelerij
·
Published
2018-03-12
·
Updated
2018-10-18
·
CVE-2017-2585
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Red Hat Keycloak versions prior to 2.5.1
Description:
The issue is related to the implementation of HMAC verification for JWS tokens, which uses a method that runs in non-constant time. This potentially leaves the application vulnerable to timing attacks.
Recommendations:
For versions prior to 2.5.1, update to version 2.5.1 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak
Red Hat Keycloak