First published: Thu Jul 11 2019(Updated: )
A vulnerability was found in keycloak. A CSRF attack can be performed in My Resources functionality in the Account Console. The attacker can trick the user to perform operations by using social engineering or any other mean that can result in a request to Keycloak from an untrusted domain. References: <a href="https://issues.jboss.org/browse/KEYCLOAK-10775">https://issues.jboss.org/browse/KEYCLOAK-10775</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/keycloak | <7.0.0 | 7.0.0 |
Keycloak | <=6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-10199 has been assigned a medium severity rating due to its potential for CSRF attacks targeting the My Resources functionality.
To fix CVE-2019-10199, upgrade your Keycloak installation to version 7.0.0 or later.
CVE-2019-10199 affects Keycloak versions up to and including 6.0.1.
CVE-2019-10199 is associated with a Cross-Site Request Forgery (CSRF) attack.
Yes, CVE-2019-10199 can be exploited through social engineering tactics to trick users into making unauthorized requests.