9.8
CVE-2017-7474
- EPSS 2.54%
- Veröffentlicht 12.05.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.0
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.0 Update cr1
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.1
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.2
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.3
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.4
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.5
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.6
Keycloak ≫ Keycloak-nodejs-auth-utils Version 2.5.7
Keycloak ≫ Keycloak-nodejs-auth-utils Version 3.0.0
Keycloak ≫ Keycloak-nodejs-auth-utils Version 3.0.0 Update cr1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.54% | 0.829 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-253 Incorrect Check of Function Return Value
The product incorrectly checks a return value from a function, which prevents it from detecting errors or exceptional conditions.
http://rhn.redhat.com/errata/RHSA-2017-1203.html
https://bugzilla.redhat.com/show_bug.cgi?id=1445271