CVE-2017-12159
published 2017-10-26CVE-2017-12159: It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.40%
82.2th percentile
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | keycloak | — | — |
| redhat | single_sign_on | — | — |
| redhat | single_sign_on | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Keycloak CSRF Vulnerability
osv·2022-05-13
CVE-2017-12159 [HIGH] Keycloak CSRF Vulnerability
Keycloak CSRF Vulnerability
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
GHSA
Keycloak CSRF Vulnerability
ghsa·2022-05-13
CVE-2017-12159 [HIGH] CWE-613 Keycloak CSRF Vulnerability
Keycloak CSRF Vulnerability
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
Red Hat
keycloak: CSRF token fixation
vendor_redhat·2017-10-17·CVSS 7.5
CVE-2017-12159 [HIGH] CWE-613 keycloak: CSRF token fixation
keycloak: CSRF token fixation
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
Package: keycloak (Red Hat Mobile Application Platform 4) - Not affected
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/101601https://access.redhat.com/errata/RHSA-2017:2904https://access.redhat.com/errata/RHSA-2017:2905https://access.redhat.com/errata/RHSA-2017:2906https://bugzilla.redhat.com/show_bug.cgi?id=1484111http://www.securityfocus.com/bid/101601https://access.redhat.com/errata/RHSA-2017:2904https://access.redhat.com/errata/RHSA-2017:2905https://access.redhat.com/errata/RHSA-2017:2906https://bugzilla.redhat.com/show_bug.cgi?id=1484111
2017-10-26
Published