After careful review of CVE-2024-5203, it has been determined that the issue is not exploitable in real-world scenarios. Moreover, the exploit assumes that the attacker has access to a session code parameter that matches a cookie on the Keycloak server. However the attacker does not have access to the cookie, and can therefore not craft a malicious request.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 13 Sep 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 13 Sep 2024 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Keycloak: login csrf | Keycloak: Login CSRF |
Fri, 13 Sep 2024 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-site request forgery (CSRF) flaw was found in Keycloak and occurs due to the lack of a unique token sent during the authentication POST request, /login-actions/authenticate. This flaw allows an attacker to craft a malicious login page and trick a legitimate user of an application into authenticating with an attacker-controlled account instead of their own. | After careful review of CVE-2024-5203, it has been determined that the issue is not exploitable in real-world scenarios. Moreover, the exploit assumes that the attacker has access to a session code parameter that matches a cookie on the Keycloak server. However the attacker does not have access to the cookie, and can therefore not craft a malicious request. |
| CPEs | cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: redhat
Published:
Updated: 2024-09-13T10:15:30.617Z
Reserved: 2024-05-22T15:10:01.533Z
Link: CVE-2024-5203
Updated:
Status : Rejected
Published: 2024-06-12T09:15:20.647
Modified: 2024-09-13T11:15:10.197
Link: CVE-2024-5203
OpenCVE Enrichment
No data.
Weaknesses