JBoss KeyCloak CVE-2014-3709 Cross Site Request Forgery Vulnerability
BID:101508
Info
JBoss KeyCloak CVE-2014-3709 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 101508 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3709 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2017 12:00AM |
| Updated: | Oct 18 2017 12:00AM |
| Credit: | Florian Weimer |
| Vulnerable: |
Jboss KeyCloak 1.0.2 |
| Not Vulnerable: |
Jboss KeyCloak 1.0.3 |
Discussion
JBoss KeyCloak CVE-2014-3709 Cross Site Request Forgery Vulnerability
JBoss KeyCloak is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected application. Other attacks are also possible.
Versions prior to JBoss KeyCloak 1.0.3 are vulnerable.
JBoss KeyCloak is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected application. Other attacks are also possible.
Versions prior to JBoss KeyCloak 1.0.3 are vulnerable.
Exploit / POC
JBoss KeyCloak CVE-2014-3709 Cross Site Request Forgery Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
JBoss KeyCloak CVE-2014-3709 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
JBoss KeyCloak CVE-2014-3709 Cross Site Request Forgery Vulnerability
References:
References:
- CVE-2014-3709 (Redhat)
- JBoss Homepage (JBoss)
- Bug 1154971 - (CVE-2014-3709) CVE-2014-3709 JBoss KeyCloak: SocialResource call (Redhat)
- CVE-2014-3709 SocialResource callback CSRF (jboss.org)