CVE-2020-1731
published 2020-03-02CVE-2020-1731: A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.28%
66.9th percentile
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak_operator | < 8.0.2 | 8.0.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Predictable password in Keycloak
ghsa·2020-04-15
CVE-2020-1731 [CRITICAL] CWE-330 Predictable password in Keycloak
Predictable password in Keycloak
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
OSV
Predictable password in Keycloak
osv·2020-04-15
CVE-2020-1731 [CRITICAL] Predictable password in Keycloak
Predictable password in Keycloak
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
Red Hat
keycloak: generates same admin password while installation when deployed on same openshift namespace
vendor_redhat·2020-02-25·CVSS 9.1
CVE-2020-1731 [CRITICAL] CWE-341 keycloak: generates same admin password while installation when deployed on same openshift namespace
keycloak: generates same admin password while installation when deployed on same openshift namespace
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
A flaw was found in the Keycloak operator (community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
Mitigation: No known mitigation yet.
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25675 ImageMagick: outside the range of representable values of type 'long' and integer overflow at MagickCore/transform.c and MagickCore/image.c
bugzilla·2020-10-27·CVSS 3.3
CVE-2020-25675 [LOW] CVE-2020-25675 ImageMagick: outside the range of representable values of type 'long' and integer overflow at MagickCore/transform.c and MagickCore/image.c
CVE-2020-25675 ImageMagick: outside the range of representable values of type 'long' and integer overflow at MagickCore/transform.c and MagickCore/image.c
In ImageMagick 7.0.8-68 there are 6 outside the range of representable values of type 'long' and 2 integer overflow at MagickCore/transform.c,image.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1731
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/64dc80b2e1907f7f20bf34d4df9483f938b0de71
Discussion:
Flaw summary:
In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer overflow and out-of-range values as reported by UndefinedBehaviorSanitizer. Such issues could
Bugzilla
CVE-2020-1731 keycloak: generates same admin password while installation when deployed on same openshift namespace
bugzilla·2020-02-11·CVSS 9.1
CVE-2020-1731 [CRITICAL] CVE-2020-1731 keycloak: generates same admin password while installation when deployed on same openshift namespace
CVE-2020-1731 keycloak: generates same admin password while installation when deployed on same openshift namespace
An issue was found in keycloak operator (community only) where Operator will generate a random admin password when installing Keycloak but this password found to be same every time when deployed to the same OpenShift namespace.
Reference:
https://issues.redhat.com/browse/KEYCLOAK-12957
Discussion:
Mitigation:
No known mitigation yet.
---
Acknowledgments:
Name: David Ffrench (Red Hat)
2020-03-02
Published