Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3875

Опубликовано: 12 июн. 2019
Источник: nvd
CVSS3: 6.5
CVSS3: 4.8
CVSS2: 5.8
EPSS Низкий

Описание

A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
Версия до 6.0.2 (исключая)
cpe:2.3:a:redhat:single_sign-on:7.3:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00047
Низкий

6.5 Medium

CVSS3

4.8 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 6.5
redhat
больше 6 лет назад

A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.

CVSS3: 6.5
debian
больше 6 лет назад

A vulnerability was found in keycloak before 6.0.2. The X.509 authenti ...

CVSS3: 4.8
github
больше 6 лет назад

Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak

EPSS

Процентиль: 15%
0.00047
Низкий

6.5 Medium

CVSS3

4.8 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295
CWE-295