CVE-2019-10199: CSRF
A vulnerability was found in keycloak. A CSRF attack can be performed in My Resources functionality in the Account Console. The attacker can trick the user to perform operations by using social engineering or any other mean that can result in a request to Keycloak from an untrusted domain.
References: https://issues.jboss.org/browse/KEYCLOAK-10775
Other sources
It was found that Keycloak's account console did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-10199?
CVE-2019-10199 has been assigned a medium severity rating due to its potential for CSRF attacks targeting the My Resources functionality.
How do I fix CVE-2019-10199?
To fix CVE-2019-10199, upgrade your Keycloak installation to version 7.0.0 or later.
Which versions of Keycloak are affected by CVE-2019-10199?
CVE-2019-10199 affects Keycloak versions up to and including 6.0.1.
What type of attack is associated with CVE-2019-10199?
CVE-2019-10199 is associated with a Cross-Site Request Forgery (CSRF) attack.
Can CVE-2019-10199 be exploited via social engineering?
Yes, CVE-2019-10199 can be exploited through social engineering tactics to trick users into making unauthorized requests.