PT-2021-9719 · Red Hat · Red Hat Single Sign-On

Dave Baker

·

Published

2021-01-12

·

Updated

2021-01-19

·

CVE-2020-14341

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Single Sign On versions 7.x
Description The issue allows an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of their choosing, originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may gather information about hosts and ports they do not have access to scan directly.
Recommendations For Red Hat Single Sign On version 7.x, consider restricting access to the "Test Connection" feature in the application console to minimize the risk of exploitation. As a temporary workaround, disabling the "Test Connection" functionality may help until a more permanent solution is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14341

Affected Products

Red Hat Single Sign-On