Red Hat Bugzilla – Bug 1144817
CVE-2014-3655 JBoss KeyCloak: Soft Token deletion via CSRF
Last modified: 2016-02-02 19:56:55 EST
It was discovered that JBoss KeyCloak's soft token removal endpoint was vulnerable to Cross-Site Request Forgery (CSRF) attacks. A remote attacker could provide a specially-crafted web page that, when visited by a user authenticated by KeyCloak, could allow the attacker to remove a soft token registerd to the user.
Upstream Issue: https://issues.jboss.org/browse/KEYCLOAK-705
Acknowledgements: This issue was discovered by Florian Weimer of Red Hat Product Security.
Victims Record: https://github.com/victims/victims-cve-db/blob/master/database/java/2014/3655.yaml