PT-2017-3737 · Red Hat+1 · Keycloak+2

Adam Mariš

·

Published

2017-09-26

·

Updated

2019-01-23

·

CVE-2017-2582

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Keycloak versions prior to 2.5.1 Picketlink (affected versions not specified) Redhat Jboss Enterprise Application Platform (affected versions not specified) Redhat Keycloak (affected versions not specified)
Description: The issue is related to the parsing of SAML messages by the StaxParserUtil class, which replaces special strings for obtaining attribute values with system properties. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property, which could be obtained in the "InResponseTo" field in the response. The vulnerability is associated with inadequate input processing when analyzing SAML messages, allowing a remote attacker to disclose protected information about system parameters using specially crafted SAML messages.
Recommendations: For Keycloak versions prior to 2.5.1: Update to version 2.5.1 or later to resolve the issue. For Picketlink: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Redhat Jboss Enterprise Application Platform: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Redhat Keycloak: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00225
CVE-2017-2582
GHSA-C77R-6F64-478Q
RHSA-2017:2808
RHSA-2017:2809
RHSA-2017:2811
RHSA-2017:3216
RHSA-2017:3217
RHSA-2017:3218
RHSA-2017:3219
RHSA-2018:2741
RHSA-2018:2742
RHSA-2018:2743
RHSA-2019:0136
RHSA-2019:0137

Affected Products

Red Hat Jboss Enterprise Application Platform
Keycloak
Picketlink