VDB
RHSA-2019%3A2483
RHSA-2019%3A2483
PUBLISHED
CVSS 4.599999904632568 MEDIUM
It was found that Keycloak's account console did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
Risk Scores
CVSS 3.0
4.599999904632568
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Single Sign-On 7.3.3 zip |
Timeline
- Aug 13, 2019 CVE Published
- Mar 18, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2019:2483 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=core.service.rhsso&downloadType=securityPatches&version=7.3 advisory
- https://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.3/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1728609 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1729261 issue
- https://issues.redhat.com/browse/KEYCLOAK-10286 advisory
- https://issues.redhat.com/browse/KEYCLOAK-10398 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_2483.json advisory
- https://access.redhat.com/security/cve/CVE-2019-10199 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10199 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10199 advisory
- https://access.redhat.com/security/cve/CVE-2019-10201 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10201 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10201 advisory