4.3
CVSSv2

CVE-2017-12161

Published: 21/02/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

It was found that keycloak prior to 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

keycloak keycloak

Vendor Advisories

it was found that keycloak would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks ...