Vulnerability Description
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Keycloak | <= 6.0.1 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10199Issue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10199Issue TrackingVendor Advisory
FAQ
What is CVE-2019-10199?
CVE-2019-10199 is a vulnerability with a CVSS score of 8.8 (HIGH). It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing opera...
How severe is CVE-2019-10199?
CVE-2019-10199 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10199?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Keycloak.