« Volver al listado

CVE-2017-7474

Estado: ModificadaCrítica (9.8)—

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-7474",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "Red Hat, Inc.",
          "product": "Keycloak Node.js adapter",
          "versions": [
            {
              "status": "affected",
              "version": "2.5 - 3.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-05-12T19:29:00.160",
  "references": [
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2017-1203.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1445271",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2017-1203.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1445271",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-253"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly.  An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks."
    },
    {
      "lang": "es",
      "value": "Se encontró que el adaptador de Keycloak Node.js 2.5 - 3.0 no controló correctamente los símbolos no válidos. Un atacante podría utilizar esta falla para omitir la autenticación y obtener acceso a información restringida, o posiblemente llevar a cabo otros ataques."
    }
  ],
  "lastModified": "2026-06-17T01:24:25.230",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "293C81B0-D88C-4219-AB11-CD85144E56FE"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.0:cr1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A926EAEF-798A-4CE0-862F-3D9B5BDC0613"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D9EC356-A999-4CFB-8091-AEA76FAB0CE2"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A48D798-909D-457F-8D0D-74CD686679E7"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA0DBE63-7B46-4841-BE10-F0EDE7B2F8A8"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5AA4E71-08F5-4CCB-B0C8-3D140704BF4F"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFD34084-6B9F-43A8-B0EC-B5ABCED7862B"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1366536F-BA86-49CB-98FB-6C0AA80B4B87"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:2.5.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6904521-34F0-4481-8914-5EEF385D2249"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16BA3E71-4CC7-4E35-AA9F-AFB41C66AD5F"
            },
            {
              "criteria": "cpe:2.3:a:keycloak:keycloak-nodejs-auth-utils:3.0.0:cr1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC11E39C-767D-4385-9371-DC03A8DD1E30"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}