Lucene search

K
osvGoogleOSV:GHSA-7FMW-85QM-H22P
HistoryMay 13, 2022 - 1:38 a.m.

Keycloak CSRF Vulnerability

2022-05-1301:38:14
Google
osv.dev
13
keycloak
csrf
vulnerability
non-unique
cookie
attacker
access
information disclosure
attacks

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

70.7%

It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

70.7%