CVE-2020-14359
Summary
| CVE | CVE-2020-14359 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-23 13:15:00 UTC |
| Updated | 2022-08-10 20:28:00 UTC |
| Description | A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jetty). This means there is no protection when we put a Gatekeeper in front of a Jetty server and use lowercase headers. |
Risk And Classification
Problem Types: CWE-305
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Login server redirect | MISC | issues.jboss.org | Issue Tracking, Third Party Advisory |
| 1868591 – (CVE-2020-14359) CVE-2020-14359 keycloak: gatekeeper bypass via cURL when using lower case HTTP headers | MISC | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.