Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-1728


A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.


Published

2020-04-06T14:15:12.607

Last Modified

2024-11-21T05:11:15.290

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-358
  • Type: Primary
    CWE-1021

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat keycloak < 10.0.0 Yes
Application quarkus quarkus ≤ 1.4.2 Yes

References