Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3856

Опубликовано: 04 окт. 2021
Источник: redhat
CVSS3: 4.3

Описание

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat A-MQ Onlinekeycloak-servicesOut of support scope
Red Hat Single Sign-On 7.6 for RHEL 7rh-sso7FixedRHBA-2022:545230.06.2022
Red Hat Single Sign-On 7.6 for RHEL 7rh-sso7-javapackages-toolsFixedRHBA-2022:545230.06.2022
Red Hat Single Sign-On 7.6 for RHEL 7rh-sso7-keycloakFixedRHBA-2022:545230.06.2022
Red Hat Single Sign-On 7.6 for RHEL 8rh-sso7FixedRHBA-2022:545430.06.2022
Red Hat Single Sign-On 7.6 for RHEL 8rh-sso7-javapackages-toolsFixedRHBA-2022:545430.06.2022
Red Hat Single Sign-On 7.6 for RHEL 8rh-sso7-keycloakFixedRHBA-2022:545430.06.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2010164keycloak-services: ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.

CVSS3: 4.3
debian
больше 3 лет назад

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows read ...

CVSS3: 4.3
github
больше 3 лет назад

Keycloak has Files or Directories Accessible to External Parties

4.3 Medium

CVSS3