First published: Wed Nov 13 2019(Updated: )
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Keycloak | <=1.0.1 | |
Redhat Jboss Enterprise Web Server | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3655 is medium with a CVSS score of 4.3.
The vulnerability affects Redhat Keycloak 1.0.1 and earlier versions, allowing soft token deletion via CSRF.
The vulnerability affects Redhat Jboss Enterprise Web Server 1.0.0, allowing soft token deletion via CSRF.
Upgrade Redhat Keycloak to a version higher than 1.0.1 to fix the vulnerability.
Upgrade Redhat Jboss Enterprise Web Server to version 1.0.1 or later to fix the vulnerability.