CVE-2019-10199

It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10199 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*

History

28 Oct 2021, 12:14

Type Values Removed Values Added
CWE CWE-20 CWE-352

Information

Published : 2019-08-14 17:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-10199

Mitre link : CVE-2019-10199

CVE.ORG link : CVE-2019-10199


JSON object : View

Products Affected

redhat

  • keycloak
CWE
CWE-352

Cross-Site Request Forgery (CSRF)