Lucene search

K
osvGoogleOSV:CVE-2017-2585
HistoryMar 12, 2018 - 3:29 p.m.

CVE-2017-2585

2018-03-1215:29:00
Google
osv.dev
7

AI Score

6

Confidence

High

EPSS

0.004

Percentile

73.5%

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.

AI Score

6

Confidence

High

EPSS

0.004

Percentile

73.5%