MEDIUM 5.9 Maven

keycloak-core vulnerable to timing attacks against JWS token verification

GHSA-w6gv-3r3v-gwgj · CVE-2017-2585

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.

Ready to move

Start Securing

Free, no credit card | First findings in minutes