{"api_version":"1","generated_at":"2026-07-23T06:09:01+00:00","cve":"CVE-2019-10199","urls":{"html":"https://cve.report/CVE-2019-10199","api":"https://cve.report/api/cve/CVE-2019-10199.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10199","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10199"},"summary":{"title":"CVE-2019-10199","description":"It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-08-14 17:15:00","updated_at":"2021-10-28 12:14:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10199","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10199","refsource":"CONFIRM","tags":["Issue Tracking","Vendor Advisory"],"title":"1729261 – (CVE-2019-10199) CVE-2019-10199 keycloak: CSRF check missing in My Resources functionality in the Account Console","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10199","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10199","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10199","vulnerable":"1","versionEndIncluding":"6.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"keycloak","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-10199","qid":"980246","title":"Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-p5xp-6vpf-jwvh)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-10199","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Red Hat","product":{"product_data":[{"product_name":"keycloak","version":{"version_data":[{"version_value":"up to keycloak 6.0.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-352"}]}]},"references":{"reference_data":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10199","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10199","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain."}]},"impact":{"cvss":[[{"vectorString":"4.6/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","version":"3.0"}]]}},"nvd":{"publishedDate":"2019-08-14 17:15:00","lastModifiedDate":"2021-10-28 12:14:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*","versionEndIncluding":"6.0.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10199","Ordinal":"148416","Title":"CVE-2019-10199","CVE":"CVE-2019-10199","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10199","Ordinal":"1","NoteData":"It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10199","Ordinal":"2","NoteData":"2019-08-14","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10199","Ordinal":"3","NoteData":"2019-08-14","Type":"Other","Title":"Modified"}]}}}