Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4209
HistoryMay 09, 2017 - 1:32 a.m.

Privilege Escalation Through Authentication Bypass

2017-05-0901:32:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.002

Percentile

56.9%

keycloak-auth-utils is vulnerable to privilege escalation attacks. The vulnerability is possible because it does not properly perform the token validation in validateGrant(). Therefore, attackers can bypass the authentication with invalid tokens and perform unauthorized access to the restricted information and possibly launch other attacks.

EPSS

0.002

Percentile

56.9%