PT-2021-9721 · Red Hat+1 · Keycloak Gatekeeper+1
Dhananjay Arunesh
+2
·
Published
2021-02-23
·
Updated
2022-08-10
·
CVE-2020-14359
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Keycloak Gatekeeper versions all
Description
A vulnerability was found in Keycloak Gatekeeper where an attacker can bypass the Gatekeeper by using lower case HTTP headers, for example, via cURL. This issue is particularly problematic when the Gatekeeper is used in front of certain webservers, such as Jetty, which also accept lower case headers, thereby providing no protection.
Recommendations
As a temporary workaround, consider restricting the use of lower case HTTP headers until a patch is available.
Avoid using lower case headers in API endpoints, such as
/api/v1/login, until the issue is resolved.
Restrict access to the Gatekeeper when used in front of a Jetty server to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetty
Keycloak Gatekeeper