CVE-2020-4931
published 2021-02-24CVE-2020-4931: IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM…
PriorityP427medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.10%
61.8th percentile
IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14389 keycloak: user can manage resources with just "view-profile" role using new Account Console
bugzilla·2020-09-04·CVSS 8.1
CVE-2020-14389 [HIGH] CVE-2020-14389 keycloak: user can manage resources with just "view-profile" role using new Account Console
CVE-2020-14389 keycloak: user can manage resources with just "view-profile" role using new Account Console
A vulnerability was found in keycloak, where a user with only view-profile role is able to manage the resources in new account console.
References:
https://issues.redhat.com/browse/KEYCLOAK-15295
Discussion:
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4.3
Via RHSA-2020:4931 https://access.redhat.com/errata/RHSA-2020:4931
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4 for RHEL 7
Via RHSA-2020:4930 https://access.redhat.com/errata/RHSA-2020:4930
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4 for RHEL 6
Via RHSA-2020:4929 https://access.redhat.com/errata/R
Bugzilla
CVE-2020-10776 keycloak: OIDC redirect_uri allows dangerous schemes resulting in potential XSS
bugzilla·2020-06-16·CVSS 4.8
CVE-2020-10776 [MEDIUM] CVE-2020-10776 keycloak: OIDC redirect_uri allows dangerous schemes resulting in potential XSS
CVE-2020-10776 keycloak: OIDC redirect_uri allows dangerous schemes resulting in potential XSS
OIDC redirect_uri allows dangerous schemes resulting in potential XSS
https://issues.redhat.com/browse/KEYCLOAK-14306
Discussion:
Mitigation:
Trusted Hosts Policy could be used to mitigate this attack :
https://www.keycloak.org/docs/latest/securing_apps/index.html#client-registration-policies
---
Acknowledgments:
Name: Lauritz Holtmann (@_lauritz_) (Chair for Network and Data Security at Ruhr University Bochum)
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4.3
Via RHSA-2020:4931 https://access.redhat.com/errata/RHSA-2020:4931
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4 for RHEL 7
Via RHSA-2020:4930
2021-02-24
Published