CVE-2020-35509
published 2022-08-23CVE-2020-35509: A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.29%
21.3th percentile
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | — | — |
| redhat | keycloak | — | — |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Keycloak vulnerable to Improper Certificate Validation
osv·2022-08-24
CVE-2020-35509 [MEDIUM] Keycloak vulnerable to Improper Certificate Validation
Keycloak vulnerable to Improper Certificate Validation
keycloak accepts an expired certificate by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
This issue was partially fixed in version [13.0.1](https://github.com/keycloak/keycloak/pull/6330) and more completely fixed in version [14.0.0](https://github.com/keycloak/keycloak/pull/8067).
GHSA
Keycloak vulnerable to Improper Certificate Validation
ghsa·2022-08-24
CVE-2020-35509 [MEDIUM] CWE-20 Keycloak vulnerable to Improper Certificate Validation
Keycloak vulnerable to Improper Certificate Validation
keycloak accepts an expired certificate by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
This issue was partially fixed in version [13.0.1](https://github.com/keycloak/keycloak/pull/6330) and more completely fixed in version [14.0.0](https://github.com/keycloak/keycloak/pull/8067).
Red Hat
keycloak: X509 Direct Grant Auth does not verify certificate timestamp validity
vendor_redhat·2021-01-04·CVSS 5.4
CVE-2020-35509 [MEDIUM] CWE-20 keycloak: X509 Direct Grant Auth does not verify certificate timestamp validity
keycloak: X509 Direct Grant Auth does not verify certificate timestamp validity
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in keycloak. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
Package: keycloak (Red Hat Decision Manager 7) - Not affected
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Integration Camel K 1) - Not affected
Package: keycloak (Red Hat OpenShi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-23
Published