Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c77r-6f64-478q

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

keycloak-core discloses system properties

It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 2.5.1

2.5.1

EPSS

Процентиль: 71%
0.00663
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-201

Связанные уязвимости

CVSS3: 6.5
redhat
больше 8 лет назад

It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.

CVSS3: 6.5
nvd
больше 7 лет назад

It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.

CVSS3: 6.5
debian
больше 7 лет назад

It was found that while parsing the SAML messages the StaxParserUtil c ...

CVSS3: 6.5
fstec
больше 8 лет назад

Уязвимость класса StaxParserUtil программного обеспечения Picketlink для управления безопасностью и идентификацией приложений Java, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 71%
0.00663
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-201