CVE Vulnerabilities

CVE-2019-14820

Published: Jan 08, 2020 | Modified: Oct 29, 2021
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.3 LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Ubuntu

It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.

Affected Software

Name Vendor Start Version End Version
Keycloak Redhat * 8.0.0 (excluding)
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 RedHat keycloak-adapter-sso7_3-eap6-0:4.8.13-1.Final_redhat_00001.1.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 RedHat keycloak-adapter-sso7_3-eap6-0:4.8.13-1.Final_redhat_00001.1.ep6.el7 *
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 RedHat eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el6eap *
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 RedHat eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 RedHat eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el8eap *
Red Hat Single Sign-On 7.3.4 zip RedHat keycloak *
Red Hat Single Sign-On 7.3 for RHEL 6 RedHat rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el6sso *
Red Hat Single Sign-On 7.3 for RHEL 7 RedHat rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el7sso *
Red Hat Single Sign-On 7.3 for RHEL 7 RedHat rh-sso7-libunix-dbus-java-0:0.8.0-2.el7sso *
Red Hat Single Sign-On 7.3 for RHEL 8 RedHat rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el8sso *
Text-Only RHOAR RedHat *

References