PT-2020-2762 · Red Hat · Keycloak Operator

Paramvir Jindal

·

Published

2020-03-02

·

Updated

2022-01-01

·

CVE-2020-1731

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keycloak operator versions prior to 8.0.2
Description The issue is related to the Keycloak operator's failure to reset a randomly generated admin password after installation. This could allow a remote attacker to elevate their privileges. The problem arises because the operator generates a random admin password when installing Keycloak, but this password remains unchanged when deployed to the same OpenShift namespace.
Recommendations For versions prior to 8.0.2, update to version 8.0.2 or later to resolve the issue. As a temporary workaround, consider manually resetting the admin password after each deployment to the same OpenShift namespace to minimize the risk of exploitation.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02854
CVE-2020-1731
GHSA-6PMV-7PR9-CGRJ

Affected Products

Keycloak Operator