CVE-2019-3875
published 2019-06-12CVE-2019-3875: A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL…
PriorityP421medium4.8CVSS 3.0
AVNACHPRNUINSUCLILAN
EPSS
0.29%
21.1th percentile
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | < 6.0.2 | 6.0.2 |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak
osv·2019-06-27
CVE-2019-3875 [MEDIUM] Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak
Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.
GHSA
Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak
ghsa·2019-06-27
CVE-2019-3875 [MEDIUM] CWE-295 Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak
Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.
Red Hat
keycloak: missing signatures validation on CRL used to verify client certificates
vendor_redhat·2019-06-11·CVSS 6.5
CVE-2019-3875 [MEDIUM] CWE-295 keycloak: missing signatures validation on CRL used to verify client certificates
keycloak: missing signatures validation on CRL used to verify client certificates
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.
Package: keycloak (Red Hat Fuse 7) - Will not fix
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-17040 rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
bugzilla·2019-10-29·CVSS 9.8
CVE-2019-17040 [CRITICAL] CVE-2019-17040 rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
CVE-2019-17040 rsyslog: out-of-bounds read in contrib/pmdb2diag/pmdb2diag.c
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
Reference:
https://github.com/rsyslog/rsyslog/pull/3875
Discussion:
Created rsyslog tracking bugs for this issue:
Affects: fedora-all [bug 1766642]
---
Upstream commit: https://github.com/rsyslog/rsyslog/pull/3875/commits/b0894088b680666035a3418326e13bc99d4fed49
---
This flaw affects the pmdb2diag.c code file which was introduced in rsyslog-8.1903.0 which was released on 2019-03-05. Older versions of rsyslog are not affected by this flaw.
Bugzilla
CVE-2019-3875 keycloak: missing signatures validation on CRL used to verify client certificates
bugzilla·2019-03-19·CVSS 6.5
CVE-2019-3875 [MEDIUM] CVE-2019-3875 keycloak: missing signatures validation on CRL used to verify client certificates
CVE-2019-3875 keycloak: missing signatures validation on CRL used to verify client certificates
A vulnerability was found in keycloak. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ("http" or "ldap") and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.
References:
https://issues.jboss.org/browse/KEYCLOAK-9846
Upstream patch:
https://github.com/keycloak/keycloak/commit/996389d61b
2019-06-12
Published