QID 981140
QID 981140: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-c77r-6f64-478q)
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c77r-6f64-478q for updates pertaining to this vulnerability.
Vendor References
- GHSA-c77r-6f64-478q -
github.com/advisories/GHSA-c77r-6f64-478q
CVEs related to QID 981140
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c77r-6f64-478q | org.keycloak:keycloak-core |
|