CVE-2021-20202
published 2021-05-12CVE-2021-20202: A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions…
PriorityP339high7.3CVSS 3.1
AVLACLPRLUINSUCHIHAL
EPSS
0.30%
22.0th percentile
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this vulnerability is to data confidentiality and integrity.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 13.0.0 | 13.0.0 |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Temporary Directory Hijacking Vulnerability in Keycloak
osv·2022-03-18
CVE-2021-20202 [HIGH] Temporary Directory Hijacking Vulnerability in Keycloak
Temporary Directory Hijacking Vulnerability in Keycloak
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this vulnerability is to data confidentiality and integrity.
GHSA
Temporary Directory Hijacking Vulnerability in Keycloak
ghsa·2022-03-18
CVE-2021-20202 [HIGH] CWE-377 Temporary Directory Hijacking Vulnerability in Keycloak
Temporary Directory Hijacking Vulnerability in Keycloak
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this vulnerability is to data confidentiality and integrity.
Red Hat
keycloak: Temporary Directory Hijacking Vulnerability in Keycloak
vendor_redhat·2021-03-16·CVSS 7.3
CVE-2021-20202 [HIGH] CWE-377 keycloak: Temporary Directory Hijacking Vulnerability in Keycloak
keycloak: Temporary Directory Hijacking Vulnerability in Keycloak
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this vulnerability is to data confidentiality and integrity.
Mitigation: By switching to the `Files` API, you are allowe
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-12
Published