CVE-2019-10157
—CVSS 3.0
5.5 medium
EPSS
<1%p11
Published
()
Modified
Description
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.
- Vendors
- redhat
- Products
- keycloak, single sign-on
- Weakness
- CWE-345, CWE-287
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.