Lucene search

K
cvelistRedhatCVELIST:CVE-2017-2585
HistoryMar 12, 2018 - 3:00 p.m.

CVE-2017-2585

2018-03-1215:00:00
redhat
www.cve.org
4

AI Score

6.2

Confidence

High

EPSS

0.004

Percentile

73.5%

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.

CNA Affected

[
  {
    "product": "keycloak",
    "vendor": "Red Hat, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "2.5.1"
      }
    ]
  }
]

AI Score

6.2

Confidence

High

EPSS

0.004

Percentile

73.5%