CVE-2017-15111: Medium severity keycloak vulnerability
A flaw was discovered in keycloak-httpd-client-install version 0.6-2. The --log-file option in keycloakcli.py insecurely passes the script name for the log file creation.
Other sources
It was discovered that keycloak-httpd-client-install uses a predictable log file name in /tmp. A local attacker could create a symbolic link to a sensitive location, possibly causing data corruption or denial of service.
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15111?
CVE-2017-15111 is classified as a medium-severity vulnerability.
How do I fix CVE-2017-15111?
To resolve CVE-2017-15111, upgrade to keycloak-httpd-client-install version 0.8 or higher.
Who is affected by CVE-2017-15111?
CVE-2017-15111 affects keycloak-httpd-client-install versions before 0.8 on both Red Hat and pip installations.
What type of vulnerability is CVE-2017-15111?
CVE-2017-15111 is a symbolic link vulnerability that allows local attackers to overwrite files.
What software packages are impacted by CVE-2017-15111?
The impacted packages include keycloak-httpd-client-install and keycloak versions prior to 0.8.