Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14910

Опубликовано: 03 дек. 2019
Источник: redhat
CVSS3: 9.3
EPSS Низкий

Описание

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

A flaw was found in keycloak 7.x where an invalid password is accepted for user authentication when LDAP user federation and STARTTLS is used instead of SSL/TLS from the LDAP server. This can allow an attacker to log into a system using any entry for a password authentication and still gain access to the system.

Отчет

This flaw does not affect Red Hat's Single Sign On (RHSSO) product and, thus, no patch will be forthcoming.

Меры по смягчению последствий

Disabling STARTTLS will fix the authentication flaw but leave the connection to the LDAP server unencrypted. Utilizing LDAPS will add a layer of encryption back to the LDAP connection but only at the SSLv3 level which also poses problems in and of itself.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7rh-sso7-keycloakNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287->CWE-305->CWE-592
https://bugzilla.redhat.com/show_bug.cgi?id=1778265Keycloak: LDAP authentication accepts invalid passwords when using StartTLS

EPSS

Процентиль: 61%
0.00419
Низкий

9.3 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

CVSS3: 9.8
debian
около 6 лет назад

A vulnerability was found in keycloak 7.x, when keycloak is configured ...

CVSS3: 9.8
github
больше 3 лет назад

Keycloak Authentication Error

CVSS3: 9.3
fstec
около 6 лет назад

Уязвимость компонента STARTTLS программного средства для управления идентификацией и доступом Keycloak, связанная с ошибками реализации процедуры аутентификации, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 61%
0.00419
Низкий

9.3 Critical

CVSS3