CVE-2019-10157
published 2019-06-12CVE-2019-10157: It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An…
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.0th percentile
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | < 4.8.3 | 4.8.3 |
| redhat | single_sign-on | < 7.3.2 | 7.3.2 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: Node.js adapter internal NBF can be manipulated leading to DoS.
vendor_redhat·2019-06-11·CVSS 4.7
CVE-2019-10157 [MEDIUM] CWE-345 keycloak: Node.js adapter internal NBF can be manipulated leading to DoS.
keycloak: Node.js adapter internal NBF can be manipulated leading to DoS.
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.
It was found that Keycloak's Node.js adapter did not properly verify the web token received from the server in its backchannel logout. An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
GHSA
Forced Logout in keycloak-connect
ghsa·2019-06-13
CVE-2019-10157 [MEDIUM] CWE-287 Forced Logout in keycloak-connect
Forced Logout in keycloak-connect
Versions of `keycloak-connect` prior to 4.4.0 are vulnerable to Forced Logout. The package fails to validate JWT signatures on the `/k_logout` route, allowing attackers to logout users and craft malicious JWTs with NBF values that prevent user access indefinitely.
## Recommendation
Upgrade to version 4.4.0 or later.
OSV
Forced Logout in keycloak-connect
osv·2019-06-13
CVE-2019-10157 [MEDIUM] Forced Logout in keycloak-connect
Forced Logout in keycloak-connect
Versions of `keycloak-connect` prior to 4.4.0 are vulnerable to Forced Logout. The package fails to validate JWT signatures on the `/k_logout` route, allowing attackers to logout users and craft malicious JWTs with NBF values that prevent user access indefinitely.
## Recommendation
Upgrade to version 4.4.0 or later.
No detection rules found.
No public exploits indexed.
2019-06-12
Published