{"api_version":"1","generated_at":"2026-07-24T18:42:04+00:00","cve":"CVE-2017-12160","urls":{"html":"https://cve.report/CVE-2017-12160","api":"https://cve.report/api/cve/CVE-2017-12160.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-12160","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-12160"},"summary":{"title":"CVE-2017-12160","description":"It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.","state":"PUBLISHED","assigner":"redhat","published_at":"2017-10-26 17:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-285","CWE-287","CWE-285 CWE-285"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2017:2905","name":"https://access.redhat.com/errata/RHSA-2017:2905","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2017:2904","name":"https://access.redhat.com/errata/RHSA-2017:2904","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2017:2906","name":"https://access.redhat.com/errata/RHSA-2017:2906","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1484154","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1484154","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"1484154 – (CVE-2017-12160) CVE-2017-12160 keycloak: resource privilege extension via access token in oauth","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-12160","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-12160","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat, Inc.","product":"keycloak","version":"affected 3.4.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"12160","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"keycloak","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T18:28:16.585Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2017:2904","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2017:2904"},{"name":"RHSA-2017:2905","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2017:2905"},{"name":"RHSA-2017:2906","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2017:2906"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1484154"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"keycloak","vendor":"Red Hat, Inc.","versions":[{"status":"affected","version":"3.4.0"}]}],"datePublic":"2017-10-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-285","description":"CWE-285","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-10-26T16:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2017:2904","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2017:2904"},{"name":"RHSA-2017:2905","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2017:2905"},{"name":"RHSA-2017:2906","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2017:2906"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1484154"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","DATE_PUBLIC":"2017-10-17T00:00:00","ID":"CVE-2017-12160","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"keycloak","version":{"version_data":[{"version_value":"3.4.0"}]}}]},"vendor_name":"Red Hat, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-285"}]}]},"references":{"reference_data":[{"name":"RHSA-2017:2904","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2017:2904"},{"name":"RHSA-2017:2905","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2017:2905"},{"name":"RHSA-2017:2906","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2017:2906"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1484154","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1484154"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2017-12160","datePublished":"2017-10-26T17:00:00.000Z","dateReserved":"2017-08-01T00:00:00.000Z","dateUpdated":"2024-09-16T18:48:51.709Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-10-26 17:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-285","CWE-287","CWE-285 CWE-285"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*","matchCriteriaId":"6E0DE4E1-5D8D-40F3-8AC8-C7F736966158"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"12160","Ordinal":"1","Title":"CVE-2017-12160","CVE":"CVE-2017-12160","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"12160","Ordinal":"1","NoteData":"It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.","Type":"Description","Title":"CVE-2017-12160"},{"CveYear":"2017","CveId":"12160","Ordinal":"2","NoteData":"2017-10-26","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"12160","Ordinal":"3","NoteData":"2017-10-26","Type":"Other","Title":"Modified"}]}}}