QID 980815
QID 980815: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-w6gv-3r3v-gwgj)
Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w6gv-3r3v-gwgj for updates pertaining to this vulnerability.
Vendor References
- GHSA-w6gv-3r3v-gwgj -
github.com/advisories/GHSA-w6gv-3r3v-gwgj
CVEs related to QID 980815
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w6gv-3r3v-gwgj | org.keycloak:keycloak-core |
|