VDB

RHSA-2019%3A2483

RHSA-2019%3A2483 PUBLISHED CVSS 4.599999904632568 MEDIUM

It was found that Keycloak's account console did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.

Risk Scores

CVSS 3.0
4.599999904632568
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Red HatRed Hat Single Sign-On 7.3.3 zip

Timeline

  • Aug 13, 2019 CVE Published
  • Mar 18, 2026 CVE Updated
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›