The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://issues.jboss.org/browse/KEYCLOAK-765 | issue tracking exploit vendor advisory |
http://www.securityfocus.com/bid/101508 | vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1154971 | issue tracking vdb entry third party advisory |