Insecure Header Processing in Keycloak's Account Console Affecting Red Hat
CVE-2019-10199
What is CVE-2019-10199?
Keycloak's account console, prior to version 6.0.1, exhibited a significant vulnerability due to inadequate checks on HTTP headers across various requests. This oversight allowed attackers to potentially exploit authenticated users, convincing them to unknowingly execute harmful operations originating from an untrusted domain. Such an attack could compromise user data and lead to unauthorized actions within the Keycloak application, making it crucial for users to ensure they are on the latest version to mitigate this type of security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
keycloak up to keycloak 6.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved