Описание
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
It was found that keycloak exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | keycloak | Not affected | ||
| Red Hat Mobile Application Platform 4 | keycloak | Out of support scope | ||
| Red Hat OpenShift Application Runtimes | keycloak | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | keycloak-adapter-sso7_3-eap6 | Fixed | RHSA-2019:3048 | 14.10.2019 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 | keycloak-adapter-sso7_3-eap6 | Fixed | RHSA-2019:3048 | 14.10.2019 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-keycloak-adapter-sso7_3 | Fixed | RHSA-2019:3049 | 14.10.2019 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | eap7-keycloak-adapter-sso7_3 | Fixed | RHSA-2019:3049 | 14.10.2019 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | eap7-keycloak-adapter-sso7_3 | Fixed | RHSA-2019:3049 | 14.10.2019 |
| Red Hat Single Sign-On 7.3.4 zip | Fixed | RHSA-2019:3050 | 14.10.2019 | |
| Red Hat Single Sign-On 7.3 for RHEL 6 | rh-sso7-keycloak | Fixed | RHSA-2019:3044 | 14.10.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
It was found that keycloak before version 8.0.0 exposes internal adapt ...
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
EPSS
4.3 Medium
CVSS3