CVE-2019-14820
published 2020-01-08CVE-2019-14820: It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.72%
50.0th percentile
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| keycloak | keycloak | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | keycloak | < 8.0.0 | 8.0.0 |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: adapter endpoints are exposed via arbitrary URLs
vendor_redhat·2019-10-14·CVSS 4.3
CVE-2019-14820 [MEDIUM] CWE-200 keycloak: adapter endpoints are exposed via arbitrary URLs
keycloak: adapter endpoints are exposed via arbitrary URLs
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
It was found that keycloak exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
Package: keycloak (Red Hat OpenShift Application Runtimes) - Out of support scope
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
ghsa·2020-04-15
CVE-2019-14820 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
osv·2020-04-15
CVE-2019-14820 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
No detection rules found.
No public exploits indexed.
2020-01-08
Published