Lucene search

K
cveRedhatCVE-2017-7474
HistoryMay 12, 2017 - 7:29 p.m.

CVE-2017-7474

2017-05-1219:29:00
CWE-253
redhat
web.nvd.nist.gov
39
keycloak
node.js
adapter
authentication bypass
cve-2017-7474
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

56.9%

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

Affected configurations

Nvd
Vulners
Node
keycloakkeycloak-nodejs-auth-utilsMatch2.5.0
OR
keycloakkeycloak-nodejs-auth-utilsMatch2.5.0cr1
OR
keycloakkeycloak-nodejs-auth-utilsMatch2.5.1
OR
keycloakkeycloak-nodejs-auth-utilsMatch2.5.2
OR
keycloakkeycloak-nodejs-auth-utilsMatch2.5.3
OR
keycloakkeycloak-nodejs-auth-utilsMatch2.5.4
OR
keycloakkeycloak-nodejs-auth-utilsMatch2.5.5
OR
keycloakkeycloak-nodejs-auth-utilsMatch2.5.6
OR
keycloakkeycloak-nodejs-auth-utilsMatch2.5.7
OR
keycloakkeycloak-nodejs-auth-utilsMatch3.0.0
OR
keycloakkeycloak-nodejs-auth-utilsMatch3.0.0cr1
VendorProductVersionCPE
keycloakkeycloak-nodejs-auth-utils2.5.0cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.0:*:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils2.5.0cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.0:cr1:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils2.5.1cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.1:*:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils2.5.2cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.2:*:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils2.5.3cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.3:*:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils2.5.4cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.4:*:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils2.5.5cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.5:*:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils2.5.6cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.6:*:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils2.5.7cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.7:*:*:*:*:*:*:*
keycloakkeycloak-nodejs-auth-utils3.0.0cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:3.0.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CNA Affected

[
  {
    "product": "Keycloak Node.js adapter",
    "vendor": "Red Hat, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "2.5 - 3.0"
      }
    ]
  }
]

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

56.9%