CVE-2014-3655: CSRF
Published Nov 13, 2019
·Updated
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
Affected Software
2 affected components
redhat Keycloak<=1.0.1
RedHat Jboss Enterprise Web Server=1.0.0
Event History
Nov 13, 2019
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2014-3655?
The severity of CVE-2014-3655 is medium with a CVSS score of 4.3.
2
How does the vulnerability CVE-2014-3655 affect Redhat Keycloak?
The vulnerability affects Redhat Keycloak 1.0.1 and earlier versions, allowing soft token deletion via CSRF.
3
How does the vulnerability CVE-2014-3655 affect Redhat Jboss Enterprise Web Server?
The vulnerability affects Redhat Jboss Enterprise Web Server 1.0.0, allowing soft token deletion via CSRF.
4
How can I fix the vulnerability CVE-2014-3655 in Redhat Keycloak?
Upgrade Redhat Keycloak to a version higher than 1.0.1 to fix the vulnerability.
5
How can I fix the vulnerability CVE-2014-3655 in Redhat Jboss Enterprise Web Server?
Upgrade Redhat Jboss Enterprise Web Server to version 1.0.1 or later to fix the vulnerability.