PT-2020-14917 · Red Hat · Keycloak

Guilherme De Almeida Suckevicz

·

Published

2020-04-06

·

Updated

2021-03-15

·

CVE-2020-1728

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Keycloak versions (affected versions not specified)
Description A vulnerability was found in Keycloak where the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improperly Implemented Security Check for Standard

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1728
GHSA-3GG7-9Q2X-79FC
RHSA-2020:3495
RHSA-2020:3496
RHSA-2020:3497

Affected Products

Keycloak