CVE Database
/

CVE-2017-2582

Back to search

CVE-2017-2582

Published: Jul 26, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

6.5

MEDIUM

Description

It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.

VendorProductVersions

Red Hat

keycloak

affected
2.5.1

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

References

RHSA-2017:3220
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3216
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2809
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2740
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3218
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2810
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2741
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2742
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2808
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0137
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3219
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0139
vendor-advisory
x_refsource_REDHAT
1041707
vdb-entry
x_refsource_SECTRACK
RHSA-2019:0136
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2743
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3217
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2811
vendor-advisory
x_refsource_REDHAT
101046
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now