CVE-2017-12161: High severity Keycloak Keycloak vulnerability
https://issues.jboss.org/browse/KEYCLOAK-5299
Other sources
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12161?
CVE-2017-12161 is considered to have a medium severity due to the potential for URL spoofing in password reset requests.
What versions of Keycloak are affected by CVE-2017-12161?
CVE-2017-12161 affects Keycloak versions prior to 3.4.2 final.
How do I fix CVE-2017-12161?
To fix CVE-2017-12161, update Keycloak to version 3.4.2 final or later.
What kind of attack does CVE-2017-12161 enable?
CVE-2017-12161 enables an attacker to spoof URLs in password reset requests using a misconfigured client-side /etc/hosts entry.
Is there any workaround if I can't update Keycloak for CVE-2017-12161?
There are no official workarounds for CVE-2017-12161, so updating Keycloak is the recommended solution.