QID 981171
QID 981171: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-95m6-mjh3-58gm)
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-95m6-mjh3-58gm for updates pertaining to this vulnerability.
Vendor References
- GHSA-95m6-mjh3-58gm -
github.com/advisories/GHSA-95m6-mjh3-58gm
CVEs related to QID 981171
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-95m6-mjh3-58gm | org.keycloak:keycloak-core |
|