CVE-2020-14341
published 2021-01-12CVE-2020-14341: The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be…
PriorityP412low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.95%
56.9th percentile
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | red_hat_single_sign-on | — | — |
| redhat | single_sign-on | 7.0 – 7.4 | — |
CVSS provenance
nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
RHSSO: test connection function in console permits timing based port scanning
vendor_redhat·2020-11-18·CVSS 2.7
CVE-2020-14341 [LOW] CWE-385 RHSSO: test connection function in console permits timing based port scanning
RHSSO: test connection function in console permits timing based port scanning
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly.
A flaw was found in Red Hat Single Sign On. A test connection available on the application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing. By observing differences in the timings of these scans, an attacker may glea
GHSA
GHSA-2fpm-8hx3-wxj9: The "Test Connection" available in v7
ghsa_unreviewed·2022-05-24
CVE-2020-14341 [MEDIUM] CWE-385 GHSA-2fpm-8hx3-wxj9: The "Test Connection" available in v7
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14341 RHSSO: test connection function in console permits timing based port scanning
bugzilla·2020-07-23·CVSS 2.7
CVE-2020-14341 [LOW] CVE-2020-14341 RHSSO: test connection function in console permits timing based port scanning
CVE-2020-14341 RHSSO: test connection function in console permits timing based port scanning
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation.
By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly.
Discussion:
Acknowledgments:
Name: Jeremy Choi (Red Hat Product Security)
Bugzilla
CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-14341 [HIGH] CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
It was found that DICOM dissector could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14742
External References:
https://www.wireshark.org/security/wnpa-sec-2018-39.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1607334]
---
Upstream patch:
https://code.wireshark.org/review/#/c/27853/2/epan/dissectors/packet-dcm.c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed. Further updates for individ
2021-01-12
Published