Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27838

Опубликовано: 11 дек. 2020
Источник: redhat
CVSS3: 5.3

Описание

A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.

A flaw was found in keycloak. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat Integration Camel K 1keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat Single Sign-On 7rh-sso7-keycloakAffected
Red Hat support for Spring BootkeycloakNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1906797keycloak: Exploiting the client registration API

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 5 лет назад

A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 6.5
debian
почти 5 лет назад

A flaw was found in keycloak in versions prior to 13.0.0. The client r ...

CVSS3: 6.5
github
больше 3 лет назад

Keycloak discloses information without authentication

5.3 Medium

CVSS3