516
VMScore

CVE-2014-3652

Published: 15/12/2019 Updated: 19/12/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Impact: Low Public Date: 2014-10-21 CWE: CWE-601 Bugzilla: 1144281: CVE-2014-3652 JBoss KeyCloak: Open redirect vulnerability It was identified that the login redirect implementation provided by JBoss KeyCloak did not validate the redirect URL. This flaw could be used by a remote malicious user to conduct phishing attacks by redirecting users to arbitary websites.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat keycloak 1.0.1

Vendor Advisories

Impact: Low Public Date: 2014-10-21 CWE: CWE-601 Bugzilla: 1144281: CVE-2014-3652 JBoss KeyCloak: Open ...