Protection Mechanism Failure in Keycloak - CVE-2020-1728

 

Protection Mechanism Failure in Keycloak - CVE-2020-1728

Published: April 6, 2020 / Updated: October 9, 2020


Vulnerability identifier: #VU47487
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1728
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass expected security restrictions.

The vulnerability exists due to the Admin Console area in Keycloak is completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.


Affected software

Keycloak
Red Hat Single Sign-On
rh-sso7-keycloak (Red Hat package)

How to mitigate CVE-2020-1728

Install updates from vendor's website.

Keycloak - update to 10.0.0
Red Hat Single Sign-On - update to 7.4.2
rh-sso7-keycloak (Red Hat package) - addressed in versions 9.0.5-1.redhat_00001.1.el6sso, 9.0.5-1.redhat_00001.1.el7sso, 9.0.5-1.redhat_00001.1.el8sso

External References

Related Security Bulletins