Vulnerability CVE-2020-14302


Published: 2020-12-15

Description:
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter. This flaw allows a malicious user to perform replay attacks.

Type:

CWE-294

(Authentication Bypass by Capture-replay)

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Redhat -> Keycloak 

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=1849584

Copyright 2024, cxsecurity.com

 

Back to Top