CVE-2019-3868
published 2019-04-24CVE-2019-3868: Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an…
PriorityP413low3.8CVSS 3.0
AVNACLPRHUINSUCLILAN
EPSS
1.02%
59.8th percentile
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | <= 6.0.0 | — |
CVSS provenance
nvdv3.03.8LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
osv·2019-04-30
CVE-2019-3868 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user?s browser session.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
ghsa·2019-04-30
CVE-2019-3868 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user?s browser session.
Red Hat
keycloak: session hijack using the user access token
vendor_redhat·2019-04-23·CVSS 3.8
CVE-2019-3868 [LOW] CWE-200 keycloak: session hijack using the user access token
keycloak: session hijack using the user access token
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.
Package: keycloak (Red Hat Fuse 7) - Will not fix
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
Package: keycloak (Red Hat OpenShift Application Runtimes) - Affected
Package: keycloak (Red Hat support for Spring Boot) - Affected
Package: keycloak (streams for Apache Kafka) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3868 keycloak: session hijack using the user access token
bugzilla·2019-02-20·CVSS 3.8
CVE-2019-3868 [LOW] CVE-2019-3868 keycloak: session hijack using the user access token
CVE-2019-3868 keycloak: session hijack using the user access token
Keycloak allows end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.
Discussion:
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.2 for RHEL 7
Via RHSA-2019:0856 https://access.redhat.com/errata/RHSA-2019:0856
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.2 for RHEL 6
Via RHSA-2019:0857 https://access.redhat.com/errata/RHSA-2019:0857
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.2.7 zip
Via RHSA-2019:0868 https://access.redhat.com/errata/RHSA-2019:086
Bugzilla
CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
bugzilla·2019-02-14·CVSS 8.8
CVE-2019-7638 [HIGH] CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4500
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677144]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7638
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627
Bugzilla
CVE-2019-7636 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c
bugzilla·2019-02-14·CVSS 8.1
CVE-2019-7636 [HIGH] CVE-2019-7636 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c
CVE-2019-7636 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4499
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677157]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7636
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-202
Bugzilla
CVE-2019-7635 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c
bugzilla·2019-02-14·CVSS 8.1
CVE-2019-7635 [HIGH] CVE-2019-7635 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c
CVE-2019-7635 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4498
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677159]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7635
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:46
Bugzilla
CVE-2019-7637 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c
bugzilla·2019-02-14·CVSS 8.8
CVE-2019-7637 [HIGH] CVE-2019-7637 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c
CVE-2019-7637 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4497
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677152]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7637
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA
Bugzilla
CVE-2019-7573 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7573 [HIGH] CVE-2019-7573 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
CVE-2019-7573 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the
wNumCoef loop).
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4491
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676752]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7573
---
This issue has been addressed in the following products:
Red Hat Enter
Bugzilla
CVE-2019-7576 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7576 [HIGH] CVE-2019-7576 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
CVE-2019-7576 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the
wNumCoef loop).
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4490
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676756]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7576
---
This issue has been addressed in the following products:
Red Hat Ente
Bugzilla
CVE-2019-7578 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.1
CVE-2019-7578 [HIGH] CVE-2019-7578 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c
CVE-2019-7578 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4494
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676782]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7578
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2
Bugzilla
CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7572 [HIGH] CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer
over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4495
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676754]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7572
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627 https:/
Bugzilla
CVE-2019-7575 SDL: heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7575 [HIGH] CVE-2019-7575 SDL: heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c
CVE-2019-7575 SDL: heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4493
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676744]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7575
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA
Bugzilla
CVE-2019-7574 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7574 [HIGH] CVE-2019-7574 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c
CVE-2019-7574 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4496
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676750]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7574
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via
Bugzilla
CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
bugzilla·2019-02-12·CVSS 8.8
CVE-2019-7577 [HIGH] CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer
over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4492
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676510]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7577
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627 https://acc
Talos
Vulnerability Spotlight: Remote code execution vulnerability in Apple Safari
blogs_talos·2020-02-12·CVSS 8.8
[HIGH] Vulnerability Spotlight: Remote code execution vulnerability in Apple Safari
Marcin Towalski of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
The Apple Safari web browser contains a remote code execution vulnerability in its Fonts feature. If a user were to open a malicious web page in Safari, they could trigger a type confusion, resulting in memory corruption and possibly arbitrary code execution. An attacker would need to trick the user into visiting the web page by some means to trigger this vulnerability.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Apple to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsApple Safari FontFaceSet remote code execution vulnerability (TALOS-2019-0967/CVE-2020-3868)
A type confusion vulnerability exists in
http://www.securityfocus.com/bid/108061https://access.redhat.com/errata/RHSA-2019:1140https://access.redhat.com/errata/RHSA-2019:2998https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3868http://www.securityfocus.com/bid/108061https://access.redhat.com/errata/RHSA-2019:1140https://access.redhat.com/errata/RHSA-2019:2998https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3868
2019-04-24
Published