CVE-2019-14820: Infoleak
A flaw was found in keycloak. A keycloak adapter exposes internal endpoints in org.keycloak.constants.AdapterConstantsThe keycloak which can be invoked by appending the appropriate suffix (e.g. kversion) to any URL. This vulnerability might lead to an information exposure.
Other sources
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
It was found that keycloak exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-14820?
CVE-2019-14820 is a vulnerability found in Keycloak before version 8.0.0 that exposes internal adapter endpoints.
What is the severity of CVE-2019-14820?
CVE-2019-14820 has a severity rating of 4.3 (medium).
How can CVE-2019-14820 be exploited?
CVE-2019-14820 can be exploited by invoking specially-crafted URLs to access unauthorized information.
Which software versions are affected by CVE-2019-14820?
Versions 0:4.8.13-1.Final_redhat_00001.1.el6, 0:4.8.13-1.Final_redhat_00001.1.el7, 0:0.8.0-2.el7, and 0:4.8.13-1.Final_redhat_00001.1.el8 of rh-sso7-keycloak are affected by CVE-2019-14820.
Is there a fix available for CVE-2019-14820?
Yes, the fix for CVE-2019-14820 is available in version 8.0.0 of Keycloak.