CVE-2017-12161
published 2018-02-21CVE-2017-12161: It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker…
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.33%
68.0th percentile
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| keycloak | keycloak | < 3.4.2 | 3.4.2 |
| red_hat_inc | keycloak | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa8.8HIGH
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Moderate severity vulnerability that affects org.keycloak:keycloak-core
ghsa·2018-10-18·CVSS 8.8
CVE-2017-1000500 [HIGH] Moderate severity vulnerability that affects org.keycloak:keycloak-core
Moderate severity vulnerability that affects org.keycloak:keycloak-core
Withdrawn: Duplicate of CVE-2017-12161 / GHSA-959q-32g8-vvp7
OSV
Moderate severity vulnerability that affects org.keycloak:keycloak-core
osv·2018-10-18
CVE-2017-12161 [MEDIUM] Moderate severity vulnerability that affects org.keycloak:keycloak-core
Moderate severity vulnerability that affects org.keycloak:keycloak-core
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.
OSV
Moderate severity vulnerability that affects org.keycloak:keycloak-core
osv·2018-10-18·CVSS 8.8
CVE-2017-12161 [HIGH] Moderate severity vulnerability that affects org.keycloak:keycloak-core
Moderate severity vulnerability that affects org.keycloak:keycloak-core
Withdrawn: Duplicate of CVE-2017-12161 / GHSA-959q-32g8-vvp7
GHSA
Moderate severity vulnerability that affects org.keycloak:keycloak-core
ghsa·2018-10-18
CVE-2017-12161 [MEDIUM] CWE-602 Moderate severity vulnerability that affects org.keycloak:keycloak-core
Moderate severity vulnerability that affects org.keycloak:keycloak-core
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.
Red Hat
keycloak: Host header injection in password reset page can allow for poisoned URL
vendor_redhat·2017-12-14·CVSS 8.8
CVE-2017-1000500 [HIGH] CWE-99 keycloak: Host header injection in password reset page can allow for poisoned URL
keycloak: Host header injection in password reset page can allow for poisoned URL
[REJECTED CVE] A vulnerability has been identified where keycloak would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.
Statement: This flaw was found to be a duplicate of CVE-2017-12161. Please see https://access.redhat.com/security/cve/CVE-2017-12161 for information about affected products and security errata.
Package: keycloak (Red Hat Mobile Application Platform 4) - Not affected
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Not affected
Red Hat
keycloak: reset password token disclosure
vendor_redhat·2017-12-14·CVSS 8.8
CVE-2017-12161 [HIGH] CWE-602 keycloak: reset password token disclosure
keycloak: reset password token disclosure
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.
it was found that keycloak would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.
Package: keycloak (Red Hat Mobile Application Platform 4) - Will not fix
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000500 keycloak: Host header injection in password reset page can allow for poisoned URL
bugzilla·2018-01-11·CVSS 8.8
CVE-2017-1000500 [HIGH] CVE-2017-1000500 keycloak: Host header injection in password reset page can allow for poisoned URL
CVE-2017-1000500 keycloak: Host header injection in password reset page can allow for poisoned URL
Keycloak SSO versions prior to 2.x are vulnerable to Host Header Injection on the forgot password page causing the application to send a poisoned URL as the password reset link.
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-1000500
https://github.com/keycloak/keycloak-documentation/pull/268/commits/a2b58aadee42af2c375b72e86dffc2cf23cc3770
Discussion:
Attack relies on compromising /etc/hosts file and tricking user into clicking reset password link with invalid URL. Wontfix for RHMAP-4
---
*** This bug has been marked as a duplicate of bug 1484564 ***
---
Statement:
This flaw was found to be a duplicate of CVE-2017-12161. Please see https://access.redhat.com/security/cve/CVE-20
Bugzilla
CVE-2017-12161 keycloak: reset password token disclosure
bugzilla·2017-08-23·CVSS 8.8
CVE-2017-12161 [HIGH] CVE-2017-12161 keycloak: reset password token disclosure
CVE-2017-12161 keycloak: reset password token disclosure
https://issues.jboss.org/browse/KEYCLOAK-5299
Discussion:
Attack relies on compromising /etc/hosts file and tricking user into clicking reset password link with invalid URL. Wontfix for RHMAP-4
---
*** Bug 1533319 has been marked as a duplicate of this bug. ***
https://bugzilla.redhat.com/show_bug.cgi?id=1484564https://github.com/keycloak/keycloak-documentation/pull/268/commits/a2b58aadee42af2c375b72e86dffc2cf23cc3770https://bugzilla.redhat.com/show_bug.cgi?id=1484564https://github.com/keycloak/keycloak-documentation/pull/268/commits/a2b58aadee42af2c375b72e86dffc2cf23cc3770
2018-02-21
Published