cbcvebase.
CVE-2017-2585
published 2018-03-12

CVE-2017-2585: Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially…

medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.

Affected

4 ranges
VendorProductVersion rangeFixed in
red_hat_inckeycloak
redhatkeycloak< 2.5.12.5.1
redhatsingle_sign_on
redhatsingle_sign_on