Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1728

Опубликовано: 27 нояб. 2019
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.

A flaw was found in Keycloak’s Admin Console, where it is missing HTTP security headers in HTTP responses. This issue is not a direct vulnerability and may not lead to a security issue, but increases the chances of allowing attackers to exploit other security flaws. Examples of these possible exploits are servers being prone to clickjacking, channel downgrade attacks, and other similar client-based attack vectors.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkuskeycloakAffected
Red Hat Fuse 7keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakOut of support scope
Red Hat build of Quarkus 1.7.5keycloakFixedRHSA-2020:425214.10.2020
Red Hat Runtimes Spring Boot 2.2.10keycloakFixedRHSA-2020:421308.10.2020
Red Hat Single Sign-On 7.4.2FixedRHSA-2020:350118.08.2020
Red Hat Single Sign-On 7.4 for RHEL 6rh-sso7-keycloakFixedRHSA-2020:349518.08.2020
Red Hat Single Sign-On 7.4 for RHEL 7rh-sso7-keycloakFixedRHSA-2020:349618.08.2020
Red Hat Single Sign-On 7.4 for RHEL 8rh-sso7-keycloakFixedRHSA-2020:349718.08.2020
Text-Only RHOARFixedRHSA-2020:353902.09.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1800585keycloak: security headers missing on REST endpoints

EPSS

Процентиль: 33%
0.00134
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
почти 6 лет назад

A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.

CVSS3: 4.8
debian
почти 6 лет назад

A vulnerability was found in all versions of Keycloak where, the pages ...

github
почти 6 лет назад

Improper Restriction of Rendered UI Layers or Frames in Keycloak

EPSS

Процентиль: 33%
0.00134
Низкий

4.8 Medium

CVSS3