4.3
CVSSv2

CVE-2014-3655

Published: 13/11/2019 Updated: 14/11/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Impact: Low Public Date: 2014-09-20 CWE: CWE-352 Bugzilla: 1144817: CVE-2014-3655 JBoss KeyCloak: Soft Token deletion via CSRF It exists that JBoss KeyCloak's soft token removal endpoint was vulnerable to Cross-Site Request Forgery (CSRF) attacks. A remote attacker could provide a specially crafted web page that, when visited by a user authenticated by KeyCloak, could allow the malicious user to remove a soft token registerd to the user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat keycloak

redhat jboss enterprise web server 1.0.0

Vendor Advisories

Impact: Low Public Date: 2014-09-20 CWE: CWE-352 Bugzilla: 1144817: CVE-2014-3655 JBoss KeyCloak: Soft ...