OSV 1.4.0 · github-reviewed · 修改于 2022-09-17 08:55
发布时间
2018-10-19 00:48
GitHub 审查时间
2020-06-17 05:27
NVD 发布时间
—
源文件
advisories/github-reviewed/2018/10/GHSA-95m6-mjh3-58gm/GHSA-95m6-mjh3-58gm.json
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.