CVE-2020-1725
published 2021-01-28CVE-2020-1725: A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.68%
48.7th percentile
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 13.0.0 | 13.0.0 |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Incorrect Authorization in keycloak
osv·2022-02-09
CVE-2020-1725 [MEDIUM] Incorrect Authorization in keycloak
Incorrect Authorization in keycloak
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
GHSA
Incorrect Authorization in keycloak
ghsa·2022-02-09
CVE-2020-1725 [MEDIUM] CWE-668 Incorrect Authorization in keycloak
Incorrect Authorization in keycloak
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
Red Hat
keycloak-gatekeeper: improper usage of parsed claims for authorization leads to improper resource access
vendor_redhat·2021-01-19·CVSS 5.4
CVE-2020-1725 [MEDIUM] CWE-863 keycloak-gatekeeper: improper usage of parsed claims for authorization leads to improper resource access
keycloak-gatekeeper: improper usage of parsed claims for authorization leads to improper resource access
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
A flaw was found in keycloak-gatekeeper. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token. The highest threat from this vulnerability is to data confidentiality and integrity.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Mobile Application Platform 4) - Not affected
Package: keycloak (Red Hat OpenShift Application Runtimes) - Not affected
Package: r
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27756 ImageMagick: division by zero at MagickCore/geometry.c
bugzilla·2020-11-03·CVSS 5.5
CVE-2020-27756 [MEDIUM] CVE-2020-27756 ImageMagick: division by zero at MagickCore/geometry.c
CVE-2020-27756 ImageMagick: division by zero at MagickCore/geometry.c
In ImageMagick, a division by zero can lead to outside the range of representable value at MagickCore/geometry.c and signed integer overflow at MagickCore/decorate.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1725
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/f35eca82b0c294ff9d0ccad104a881c3ae2ba913
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
Flaw summary:
In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditions which also lead to undefined behavior. This flaw can be triggered by a crafted input file processed by ImageMagick and could impact application availability. The pat
Bugzilla
CVE-2020-2111 jenkins-subversion-plugin: XSS in project repository base url
bugzilla·2020-03-31·CVSS 5.4
CVE-2020-2111 [MEDIUM] CVE-2020-2111 jenkins-subversion-plugin: XSS in project repository base url
CVE-2020-2111 jenkins-subversion-plugin: XSS in project repository base url
A vulnerability was found in Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.
Reference:
http://www.openwall.com/lists/oss-security/2020/02/12/3
Discussion:
Created subversion tracking bugs for this issue:
Affects: fedora-all [bug 1819106]
---
External References:
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1725
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 3.11
Via RHSA-2020:2478 https://access.redhat.com/errata/RHSA-2020:2478
---
This bug is now closed. Further updates for individual produc
Bugzilla
CVE-2020-1725 keycloak-gatekeeper: improper usage of parsed claims for authorization leads to improper resource access
bugzilla·2019-10-24·CVSS 5.4
CVE-2020-1725 [MEDIUM] CVE-2020-1725 keycloak-gatekeeper: improper usage of parsed claims for authorization leads to improper resource access
CVE-2020-1725 keycloak-gatekeeper: improper usage of parsed claims for authorization leads to improper resource access
In some scenarios we mentioned that a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
Upstream Issue:
https://issues.jboss.org/browse/KEYCLOAK-11145
Discussion:
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-1725
2021-01-28
Published