CVE-2017-12159

Description

It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.588

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-12159,CVE-2017-12158 are fixed in Keycloak - keycloak-parent 3.4.0Windows
Vulnerabilities CVE-2017-12159,CVE-2017-12158 are fixed in Keycloak - keycloak-parent for Linux 3.4.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234