CVE-2020-1717: Medium severity redhat keycloak vulnerability
Published Jan 30, 2020
·Updated
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
Affected Software
5 affected components
maven/org.keycloak:keycloak-parent<=7.0.1
redhat keycloak=7.0.1
redhat Jboss Fuse=7.0.0
redhat Openshift Application Runtimes
redhat Single Sign-on=7.0
Event History
Jan 30, 2020
Data Sourced
via Red Hat·05:31 AM
DescriptionSeverityAffected Software
Feb 11, 2021
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
DescriptionWeakness
Feb 9, 2022
Advisory Published
via GitHub·12:59 AM
Frequently Asked Questions
1
What is CVE-2020-1717?
CVE-2020-1717 is a vulnerability found in Keycloak 7.0.1 that allows a logged-in user to perform an account email enumeration attack.
2
What is the severity of CVE-2020-1717?
CVE-2020-1717 has a severity rating of medium, with a severity value of 2.7.
3
Which software is affected by CVE-2020-1717?
Keycloak 7.0.1, Redhat Jboss Fuse 7.0.0, Redhat Openshift Application Runtimes, and Redhat Single Sign-on 7.0 are affected by CVE-2020-1717.
4
How can a logged-in user exploit CVE-2020-1717?
A logged-in user can exploit CVE-2020-1717 by performing an account email enumeration attack.
5
Are there any references for CVE-2020-1717?
Yes, you can find more information about CVE-2020-1717 in the following references: [Link 1], [Link 2], [Link 3].