CVE-2014-3709

CVSS v3.0 8.8 (High)
88% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.43 % (75th)
0.43% Progress
Affected Products 1
Advisories 1

The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.

Weaknesses
CWE-352
Cross-Site Request Forgery (CSRF)
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2017-10-18 14:29:00
(7 years ago)
Updated Date
2017-11-07 13:21:54
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Keycloak 1.0.2.final and prior versions cpe:2.3:a:keycloak:keycloak <= 1.0.2.final
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...