CVE-2017-12161

CVE-2017-12161

Vendor Red Hat, Inc.
Product Keycloak
Weakness CWE-602 · Client-side enforcement
Published February 21, 2018
Last update August 5, 2024

CVSS base score

What the vulnerability does

01Description

It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.

Key dates

02Disclosure timeline

February 21, 2018 CVE published
August 5, 2024 Record updated