Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1723

Опубликовано: 19 янв. 2021
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7keycloakNot affected
Red Hat Mobile Application Platform 4keycloakOut of support scope
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Single Sign-On 7rh-sso7-keycloakNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1770276keycloak: logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages

EPSS

Процентиль: 36%
0.00155
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
около 5 лет назад

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0

CVSS3: 6.1
debian
около 5 лет назад

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint ...

CVSS3: 4.3
github
больше 3 лет назад

The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks. Versions shipped with Red Hat Mobile Aplication Platform 4 are believed to be vulnerable.

EPSS

Процентиль: 36%
0.00155
Низкий

4.3 Medium

CVSS3