Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2022-3782 CVE-2022-3916 |
CWE-ID | CWE-22 CWE-613 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
rh-sso7-keycloak (Red Hat package) Operating systems & Components / Operating system package or component |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU70169
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-3782
CWE-ID:
CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform path traversal attacks.
The vulnerability exists due to insufficient validation of URLs included in a redirect. A remote attacker can construct a malicious request to bypass validation by using double encoding, access other URLs and potentially sensitive information within the domain.
MitigationInstall updates from vendor's website.
rh-sso7-keycloak (Red Hat package): before 18.0.3-1.redhat_00002.1.el9sso
External linkshttp://access.redhat.com/errata/RHSA-2022:8963
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU70166
Risk: Low
CVSSv3.1: 4.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-3916
CWE-ID:
CWE-613 - Insufficient Session Expiration
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to reuse of session ids across root and user authentication sessions when using a client with the offline_access
scope. An attacker with ability to obtain the root session ID can utilize the refresh token and authenticate to the application as another user.
The issue affects shared environments, where the attacker is able to obtain victim's cookies after the victim logs out.
Install updates from vendor's website.
rh-sso7-keycloak (Red Hat package): before 18.0.3-1.redhat_00002.1.el9sso
External linkshttp://access.redhat.com/errata/RHSA-2022:8963
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.