PT-2020-14917 · Red Hat · Keycloak
Guilherme De Almeida Suckevicz
·
Published
2020-04-06
·
Updated
2021-03-15
·
CVE-2020-1728
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak versions (affected versions not specified)
Description
A vulnerability was found in Keycloak where the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improperly Implemented Security Check for Standard
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak