The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-5850 | The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection. |
![]() |
GHSA-xr6q-qqx7-553g | JBoss Keycloak CSRF Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:50:18.003Z
Reserved: 2014-05-14T00:00:00
Link: CVE-2014-3709

No data.

Status : Deferred
Published: 2017-10-18T14:29:00.513
Modified: 2025-04-20T01:37:25.860
Link: CVE-2014-3709


No data.