PT-2020-2762 · Red Hat · Keycloak Operator
Paramvir Jindal
·
Published
2020-03-02
·
Updated
2022-01-01
·
CVE-2020-1731
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Keycloak operator versions prior to 8.0.2
Description
The issue is related to the Keycloak operator's failure to reset a randomly generated admin password after installation. This could allow a remote attacker to elevate their privileges. The problem arises because the operator generates a random admin password when installing Keycloak, but this password remains unchanged when deployed to the same OpenShift namespace.
Recommendations
For versions prior to 8.0.2, update to version 8.0.2 or later to resolve the issue. As a temporary workaround, consider manually resetting the admin password after each deployment to the same OpenShift namespace to minimize the risk of exploitation.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak Operator