PT-2021-9719 · Red Hat · Red Hat Single Sign-On
Dave Baker
·
Published
2021-01-12
·
Updated
2021-01-19
·
CVE-2020-14341
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Single Sign On versions 7.x
Description
The issue allows an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of their choosing, originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may gather information about hosts and ports they do not have access to scan directly.
Recommendations
For Red Hat Single Sign On version 7.x, consider restricting access to the "Test Connection" feature in the application console to minimize the risk of exploitation. As a temporary workaround, disabling the "Test Connection" functionality may help until a more permanent solution is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Single Sign-On