CVE-2019-10199: CSRF

Published Jul 11, 2019
·
Updated

A vulnerability was found in keycloak. A CSRF attack can be performed in My Resources functionality in the Account Console. The attacker can trick the user to perform operations by using social engineering or any other mean that can result in a request to Keycloak from an untrusted domain.

References: https://issues.jboss.org/browse/KEYCLOAK-10775

Other sources

It was found that Keycloak's account console did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.

It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.

Affected Software

2 affected componentsFixes available
redhat/keycloak<7.0.0
7.0.0
redhat Keycloak<=6.0.1

Event History

Aug 13, 2019
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 14, 2019
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2019-10199?

CVE-2019-10199 has been assigned a medium severity rating due to its potential for CSRF attacks targeting the My Resources functionality.

2

How do I fix CVE-2019-10199?

To fix CVE-2019-10199, upgrade your Keycloak installation to version 7.0.0 or later.

3

Which versions of Keycloak are affected by CVE-2019-10199?

CVE-2019-10199 affects Keycloak versions up to and including 6.0.1.

4

What type of attack is associated with CVE-2019-10199?

CVE-2019-10199 is associated with a Cross-Site Request Forgery (CSRF) attack.

5

Can CVE-2019-10199 be exploited via social engineering?

Yes, CVE-2019-10199 can be exploited through social engineering tactics to trick users into making unauthorized requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203