CVE-2020-10734
published 2021-02-11CVE-2020-10734: A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat…
PriorityP48low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.21%
11.3th percentile
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_fuse | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OIDC Logout redirect in keycloak
osv·2022-04-28
CVE-2020-10734 [LOW] OIDC Logout redirect in keycloak
OIDC Logout redirect in keycloak
A flaw was found in keycloak. The OIDC logout endpoint does not have CSRF protection. The highest threat from this vulnerability is to system availability.
GHSA
OIDC Logout redirect in keycloak
ghsa·2022-04-28
CVE-2020-10734 [LOW] CWE-601 OIDC Logout redirect in keycloak
OIDC Logout redirect in keycloak
A flaw was found in keycloak. The OIDC logout endpoint does not have CSRF protection. The highest threat from this vulnerability is to system availability.
Red Hat
keycloak: OIDC logout endpoint CSRF
vendor_redhat·2021-02-10·CVSS 3.3
CVE-2020-10734 [LOW] CWE-352 keycloak: OIDC logout endpoint CSRF
keycloak: OIDC logout endpoint CSRF
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
A flaw was found in keycloak. The OIDC logout endpoint does not have CSRF protection. The highest threat from this vulnerability is to system availability.
Package: keycloak (Red Hat Fuse 7) - Fix deferred
Package: keycloak (Red Hat OpenShift Application Runtimes) - Affected
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Affected
Package: keycloak (Red Hat support for Spring Boot) - Fix deferred
No detection rules found.
No public exploits indexed.
2021-02-11
Published