ZeroHour

CVE-2017-7474

CVSS 3.0
9.8 critical
EPSS
3%p84
Published
()
Modified
Description

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

Vendors
keycloak
Products
keycloak-nodejs-auth-utils
Weakness
CWE-253
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.