CVE Vulnerabilities

CVE-2020-1731

Predictable from Observable State

Published: Mar 02, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
9.1 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Ubuntu

A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.

Weakness

A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.

Affected Software

Name Vendor Start Version End Version
Keycloak_operator Redhat * 8.0.2 (excluding)

Potential Mitigations

References