Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1731

Опубликовано: 25 фев. 2020
Источник: redhat
CVSS3: 9.1

Описание

A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.

A flaw was found in the Keycloak operator (community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.

Меры по смягчению последствий

No known mitigation yet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7rh-sso7-keycloakNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-341
https://bugzilla.redhat.com/show_bug.cgi?id=1801713keycloak: generates same admin password while installation when deployed on same openshift namespace

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
больше 6 лет назад

A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.

CVSS3: 9.1
debian
больше 6 лет назад

A flaw was found in all versions of the Keycloak operator, before vers ...

CVSS3: 9.8
github
больше 6 лет назад

Predictable password in Keycloak

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость программного средства для управления идентификацией и доступом Keycloak operator, связанная с отсутствием сброса случайно сгенерированного пароля администратора после установки Keycloak, позволяющая нарушителю повысить свои привилегии

9.1 Critical

CVSS3