CVE-2020-1728
published 2020-04-06CVE-2020-1728: A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP…
PriorityP425medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.76%
51.6th percentile
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| quarkus | quarkus | <= 1.4.2 | — |
| redhat | keycloak | < 10.0.0 | 10.0.0 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44573 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] Two heap overflow vulnerabilities exist in oenSUSE libsolv through 13 Dec 2020 in the resolve_installed function at src/solver.c: line 1728 & 1766.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Red Hat
keycloak: security headers missing on REST endpoints
vendor_redhat·2019-11-27·CVSS 4.8
CVE-2020-1728 [MEDIUM] CWE-358 keycloak: security headers missing on REST endpoints
keycloak: security headers missing on REST endpoints
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.
A flaw was found in Keycloak’s Admin Console, where it is missing HTTP security headers in HTTP responses. This issue is not a direct vulnerability and may not lead to a security issue, but increases the chances of allowing attackers to exploit other security flaws. Examples of these possible e
OSV
Improper Restriction of Rendered UI Layers or Frames in Keycloak
osv·2020-04-15
CVE-2020-1728 [MEDIUM] Improper Restriction of Rendered UI Layers or Frames in Keycloak
Improper Restriction of Rendered UI Layers or Frames in Keycloak
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.
GHSA
Improper Restriction of Rendered UI Layers or Frames in Keycloak
ghsa·2020-04-15
CVE-2020-1728 [MEDIUM] CWE-1021 Improper Restriction of Rendered UI Layers or Frames in Keycloak
Improper Restriction of Rendered UI Layers or Frames in Keycloak
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-44573 libsolv: Heap overflow
bugzilla·2022-02-22·CVSS 3.3
CVE-2021-44573 [LOW] CVE-2021-44573 libsolv: Heap overflow
CVE-2021-44573 libsolv: Heap overflow
Two heap overflow vulnerabilities exist in oenSUSE libsolv through 13 Dec 2020 in the resolve_installed function at src/solver.c: line 1728 & 1766.
https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_installed-1766
https://github.com/openSUSE/libsolv/issues/430
https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_installed-1728
Discussion:
Created libsolv tracking bugs for this issue:
Affects: fedora-all [bug 2056776]
---
Adding CVSS v3 from Red Hat.
Bugzilla
CVE-2020-1728 keycloak: security headers missing on REST endpoints
bugzilla·2020-02-07·CVSS 4.8
CVE-2020-1728 [MEDIUM] CVE-2020-1728 keycloak: security headers missing on REST endpoints
CVE-2020-1728 keycloak: security headers missing on REST endpoints
It was found that pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.
References:
https://issues.redhat.com/browse/KEYCLOAK-12264
Discussion:
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4 for RHEL 6
Via RHSA-2020:3495 https://access.redhat.com/errata/RHSA-2020:3495
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4
2020-04-06
Published