Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1714

Опубликовано: 11 мая 2020
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.

A flaw was found in Keycloak, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.

Меры по смягчению последствий

There is currently no known mitigation for this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakAffected
Red Hat Single Sign-On 7rh-sso7-keycloakAffected
Red Hat support for Spring BootkeycloakAffected
Red Hat build of Quarkus 1.7.5keycloakFixedRHSA-2020:425214.10.2020
Red Hat Decision Manager 7keycloakFixedRHSA-2020:367508.09.2020
Red Hat Fuse 7.8.0keycloakFixedRHSA-2020:556816.12.2020
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6keycloak-adapter-sso7_4-eap6FixedRHSA-2020:281602.07.2020
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7keycloak-adapter-sso7_4-eap6FixedRHSA-2020:281602.07.2020
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6eap7-keycloak-adapter-sso7_4FixedRHSA-2020:281402.07.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1705975keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.

CVSS3: 8.8
debian
больше 5 лет назад

A flaw was found in Keycloak before version 11.0.0, where the code bas ...

CVSS3: 8.8
github
почти 4 года назад

Improper Input Validation in Keycloak

7.5 High

CVSS3