CVE-2020-1717
published 2021-02-11CVE-2020-1717: A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
PriorityP49low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.77%
51.5th percentile
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_fuse | — | — |
| redhat | keycloak | — | — |
| redhat | keycloak | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Generation of Error Message Containing Sensitive Information in Keycloak
osv·2022-02-09
CVE-2020-1717 [LOW] Generation of Error Message Containing Sensitive Information in Keycloak
Generation of Error Message Containing Sensitive Information in Keycloak
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
GHSA
Generation of Error Message Containing Sensitive Information in Keycloak
ghsa·2022-02-09
CVE-2020-1717 [LOW] CWE-209 Generation of Error Message Containing Sensitive Information in Keycloak
Generation of Error Message Containing Sensitive Information in Keycloak
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
Red Hat
Keycloak: A logged in user can do an account email enumeration attack
vendor_redhat·2021-02-10·CVSS 2.7
CVE-2020-1717 [LOW] CWE-209 Keycloak: A logged in user can do an account email enumeration attack
Keycloak: A logged in user can do an account email enumeration attack
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
A flaw was found in keycloak. An attacker could use the change email function in the account settings to determine if an email address was already used for another account (an account enumeration attack). The highest threat from this flaw is to data confidentiality.
Package: keycloak (Red Hat Fuse 7) - Fix deferred
Package: keycloak (Red Hat OpenShift Application Runtimes) - Affected
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Affected
Package: keycloak (Red Hat support for Spring Boot) - Fix deferred
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27760 ImageMagick: division by zero at MagickCore/enhance.c
bugzilla·2020-11-03·CVSS 5.5
CVE-2020-27760 [MEDIUM] CVE-2020-27760 ImageMagick: division by zero at MagickCore/enhance.c
CVE-2020-27760 ImageMagick: division by zero at MagickCore/enhance.c
In ImageMagick, there is a division by zero at MagickCore/enhance.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1717
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/c5fcdea6a6ae27cf3db20c28b176e87b1a584e06
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
Flaw summary:
In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch uses the `PerceptibleReciprocal()` to prevent the divide-by-zero from occurring.
---
Statement:
This flaw is out of support scope for
Bugzilla
CVE-2020-1717 Keycloak: A logged in user can do an account email enumeration attack
bugzilla·2020-01-30·CVSS 2.7
CVE-2020-1717 [LOW] CVE-2020-1717 Keycloak: A logged in user can do an account email enumeration attack
CVE-2020-1717 Keycloak: A logged in user can do an account email enumeration attack
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
References:
https://issues.jboss.org/browse/KEYCLOAK-12014
Discussion:
Marking RHSSO 7 as affected.
---
External References:
https://issues.redhat.com/browse/KEYCLOAK-12014
2021-02-11
Published