CVE-2019-10199

Description

It was found that Keycloaks account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.095

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-10199,CVE-2019-10201 are fixed in Keycloak-core 7.0.0Windows
Vulnerabilities CVE-2019-10199,CVE-2019-10201 are fixed in Keycloak-core for Linux 7.0.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234