{"id":"CVE-2017-7474","aliases":[],"url":"https://o3.security/vulnerability/CVE-2017-7474","summary":"keycloak-connect and keycloak-js improperly handle invalid tokens","details":"It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly.  An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.","published":"2017-11-15T20:41:51Z","modified":"2023-11-08T03:59:24.497819Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"keycloak-connect","fixedVersion":"3.1.0"},{"ecosystem":"npm","name":"keycloak-js","fixedVersion":"3.1.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7474"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1445271"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2017-1203.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:59:24.497819Z"}}