CSRF Vulnerability in JBoss KeyCloak by Red Hat
CVE-2014-3709
8.8HIGH
What is CVE-2014-3709?
The SocialResource.callback method in JBoss KeyCloak versions prior to 1.0.3.Final lacks sufficient CSRF protection, allowing remote attackers to exploit this weakness. This vulnerability enables them to initiate unauthorized actions on behalf of authenticated users, posing a significant risk to user data and application integrity. It's critical for organizations using affected versions to implement necessary security measures and upgrade to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
