It was found that while parsing the SAML messages the...
Vulnerability Description
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-2582
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2017:3220
- https://access.redhat.com/errata/RHSA-2017:3216
- https://access.redhat.com/errata/RHSA-2017:2809
- https://access.redhat.com/errata/RHSA-2018:2740
- https://access.redhat.com/errata/RHSA-2017:3218
- https://access.redhat.com/errata/RHSA-2017:2810
- https://access.redhat.com/errata/RHSA-2018:2741
- https://access.redhat.com/errata/RHSA-2018:2742
- https://access.redhat.com/errata/RHSA-2017:2808
- https://access.redhat.com/errata/RHSA-2019:0137
- https://access.redhat.com/errata/RHSA-2017:3219
- https://access.redhat.com/errata/RHSA-2019:0139
- https://github.com/keycloak/keycloak/pull/3715/commits/0cb5ba0f6e83162d221681f47b470c3042eef237
- http://www.securitytracker.com/id/1041707
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2582
- https://access.redhat.com/errata/RHSA-2019:0136
- https://access.redhat.com/errata/RHSA-2018:2743
- https://access.redhat.com/errata/RHSA-2017:3217
- https://access.redhat.com/errata/RHSA-2017:2811
- http://www.securityfocus.com/bid/101046
More from Red Hat
View All →Affected Vendor
Red Hat
View all reports →