High severity8.8NVD Advisory· Published Oct 18, 2017· Updated Jun 17, 2026
CVE-2014-3709
CVE-2014-3709
Description
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 1.0.3.Final | 1.0.3.Final |
Affected products
2Patches
Vulnerability mechanics
References
7- issues.jboss.org/browse/KEYCLOAK-765nvdExploitIssue TrackingVendor AdvisoryWEB
- www.securityfocus.com/bid/101508nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-xr6q-qqx7-553gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-3709ghsaADVISORY
- github.com/keycloak/keycloak/commit/bb132e1aa0b3b3a123883d0b8d0b788337df956dghsaWEB
- web.archive.org/web/20200227141715/http://www.securityfocus.com/bid/101508ghsaWEB
News mentions
0No linked articles in our index yet.