Improper Authentication in Keycloak - CVE-2017-12160

 

Improper Authentication in Keycloak - CVE-2017-12160

Published: October 26, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38017
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12160
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to execute arbitrary code.

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.


Affected software

Keycloak
rh-sso7-keycloak (Red Hat package)

How to mitigate CVE-2017-12160

Install update from vendor's website.

rh-sso7-keycloak (Red Hat package) - addressed in versions 2.5.14-1.Final_redhat_1.1.jbcs.el6, 2.5.14-1.Final_redhat_1.1.jbcs.el7

External References

Related Security Bulletins