GHSA-7fmw-85qm-h22p
Dashboard / Vulnerabilities / GHSA-7fmw-85qm-h22p
Summary: Keycloak CSRF Vulnerability
Details: It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-12159, https://access.redhat.com/errata/RHSA-2017:2904, https://access.redhat.com/errata/RHSA-2017:2905, https://access.redhat.com/errata/RHSA-2017:2906, https://bugzilla.redhat.com/show_bug.cgi?id=1484111, https://web.archive.org/web/20210124113906/http://www.securityfocus.com/bid/101601
Affected packages
Package
Name: org.keycloak:keycloak-parent
Purl: pkg:maven/org.keycloak/keycloak-parent
Affected ranges
Type: ECOSYSTEM
Events:
