CVE-2016-8609
published 2018-08-01CVE-2016-8609: It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from…
PriorityP338high8.1CVSS 3.0
AVNACLPRNUIRSUCHIHAN
EPSS
1.68%
74.3th percentile
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | < 2.3.0 | 2.3.0 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Authentication in org.keycloak:keycloak-core
osv·2018-10-18
CVE-2016-8609 [HIGH] Improper Authentication in org.keycloak:keycloak-core
Improper Authentication in org.keycloak:keycloak-core
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
GHSA
Improper Authentication in org.keycloak:keycloak-core
ghsa·2018-10-18
CVE-2016-8609 [HIGH] CWE-287 Improper Authentication in org.keycloak:keycloak-core
Improper Authentication in org.keycloak:keycloak-core
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
Red Hat
keycloak: account hijacking via auth code fixation
vendor_redhat·2016-12-13·CVSS 3.7
CVE-2016-8609 [LOW] CWE-384 keycloak: account hijacking via auth code fixation
keycloak: account hijacking via auth code fixation
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
It was found that the keycloak did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Not affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-2945.htmlhttp://www.securityfocus.com/bid/95070http://www.securitytracker.com/id/1037460https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8609http://rhn.redhat.com/errata/RHSA-2016-2945.htmlhttp://www.securityfocus.com/bid/95070http://www.securitytracker.com/id/1037460https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8609
2018-08-01
Published