Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14832

Опубликовано: 14 окт. 2019
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.

A flaw was found in the Keycloak REST API where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7keycloakWill not fix
Red Hat Mobile Application Platform 4keycloakOut of support scope
Red Hat OpenShift Application RuntimeskeycloakOut of support scope
Red Hat support for Spring BootkeycloakAffected
Red Hat Runtimes Spring Boot 2.1.12keycloakFixedRHSA-2020:236604.06.2020
Red Hat Single Sign-On 7.3.4 zipFixedRHSA-2019:305014.10.2019
Red Hat Single Sign-On 7.3 for RHEL 6rh-sso7-keycloakFixedRHSA-2019:304414.10.2019
Red Hat Single Sign-On 7.3 for RHEL 7rh-sso7-keycloakFixedRHSA-2019:304514.10.2019
Red Hat Single Sign-On 7.3 for RHEL 7rh-sso7-libunix-dbus-javaFixedRHSA-2019:304514.10.2019
Red Hat Single Sign-On 7.3 for RHEL 8rh-sso7-keycloakFixedRHSA-2019:304614.10.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1749487keycloak: cross-realm user access auth bypass

EPSS

Процентиль: 59%
0.00383
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.

CVSS3: 7.5
debian
больше 6 лет назад

A flaw was found in the Keycloak REST API before version 8.0.0 where i ...

CVSS3: 7.5
github
больше 3 лет назад

Keycloak Unauthenticated Access

EPSS

Процентиль: 59%
0.00383
Низкий

5 Medium

CVSS3