Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-35509

Опубликовано: 04 янв. 2021
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

A flaw was found in keycloak. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat Integration Camel K 1keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat support for Spring BootkeycloakNot affected
Red Hat Single Sign-On 7.4.9FixedRHSA-2021:353414.09.2021
Red Hat Single Sign-On 7.4 for RHEL 6rh-sso7-keycloakFixedRHSA-2021:352714.09.2021
Red Hat Single Sign-On 7.4 for RHEL 7rh-sso7-keycloakFixedRHSA-2021:352814.09.2021
Red Hat Single Sign-On 7.4 for RHEL 8rh-sso7-keycloakFixedRHSA-2021:352914.09.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1912427keycloak: X509 Direct Grant Auth does not verify certificate timestamp validity

EPSS

Процентиль: 25%
0.00087
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 5.4
debian
больше 3 лет назад

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An ...

CVSS3: 5.4
github
больше 3 лет назад

Keycloak vulnerable to Improper Certificate Validation

EPSS

Процентиль: 25%
0.00087
Низкий

4.2 Medium

CVSS3