CVE-2020-1723
published 2021-01-28CVE-2020-1723: A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.00%
58.9th percentile
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| keycloak_gatekeeper_project | keycloak_gatekeeper | — | — |
| keycloak_gatekeeper_project | keycloak_gatekeeper | — | — |
| louketo | keycloak_gatekeeper | — | — |
| louketo | keycloak_gatekeeper | — | — |
| redhat | mobile_application_platform | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages
vendor_redhat·2021-01-19·CVSS 6.1
CVE-2020-1723 [MEDIUM] CWE-601 keycloak: logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages
keycloak: logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
Package: keycloak (Red Hat OpenShift Application Runtimes) - Not affected
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Not affected
GHSA
GHSA-xf65-pwfc-rxcm: The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages
ghsa_unreviewed·2022-05-24
CVE-2020-1723 [MEDIUM] CWE-601 GHSA-xf65-pwfc-rxcm: The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages
The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks. Versions shipped with Red Hat Mobile Aplication Platform 4 are believed to be vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25663 ImageMagick: use-after-free, heap-buffer-overflow triggered by GetPixelRed, GetPixelBlue in MagickCore/pixel-accessor.h
bugzilla·2020-10-26·CVSS 5.5
CVE-2020-25663 [MEDIUM] CVE-2020-25663 ImageMagick: use-after-free, heap-buffer-overflow triggered by GetPixelRed, GetPixelBlue in MagickCore/pixel-accessor.h
CVE-2020-25663 ImageMagick: use-after-free, heap-buffer-overflow triggered by GetPixelRed, GetPixelBlue in MagickCore/pixel-accessor.h
In ImageMagick, there is a heap-use-after-free at MagickCore/pixel-accessor.h:378:10 in GetPixelRed.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1723
Discussion:
Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/a47e7a994766b92b10d4a87df8c1c890c8b170f3
Seems to be the same for https://github.com/ImageMagick/ImageMagick/issues/1723 which is the same issue but with GetPixelBlue.
---
Flaw summary:
A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-overflow READ when GetPixelRed() or GetPixelBlue()[1] was called. This could oc
Bugzilla
CVE-2020-2136 jenkins-git-plugin: stored cross-site scripting
bugzilla·2020-03-31·CVSS 5.4
CVE-2020-2136 [MEDIUM] CVE-2020-2136 jenkins-git-plugin: stored cross-site scripting
CVE-2020-2136 jenkins-git-plugin: stored cross-site scripting
A vulnerability was found in Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
Reference:
http://www.openwall.com/lists/oss-security/2020/03/09/1
Discussion:
External References:
https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1723
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 3.11
Via RHSA-2020:2478 https://access.redhat.com/errata/RHSA-2020:2478
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-2136
---
This i
Bugzilla
CVE-2020-1723 keycloak: logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages
bugzilla·2019-11-08·CVSS 6.1
CVE-2020-1723 [MEDIUM] CVE-2020-1723 keycloak: logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages
CVE-2020-1723 keycloak: logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages
The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks.
Upstream Issue:
https://issues.jboss.org/browse/KEYCLOAK-11318
Discussion:
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-1723
2021-01-28
Published