Cleartext Storage of Sensitive Information Affecting rh-sso7-keycloak package, versions <0:18.0.14-1.redhat_00001.1.el8sso


Severity

Recommended
low

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.55% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-RHSSO7KEYCLOAK-7198718
  • published4 Jun 2024
  • disclosed3 Jun 2024

Introduced: 3 Jun 2024

CVE-2024-4540  (opens in a new tab)
CWE-312  (opens in a new tab)

How to fix?

Upgrade RHEL:8 rh-sso7-keycloak to version 0:18.0.14-1.redhat_00001.1.el8sso or higher.
This issue was patched in RHSA-2024:3567.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rh-sso7-keycloak package and not the rh-sso7-keycloak package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a request_uri authorization request, possibly leading to an information disclosure vulnerability.

CVSS Base Scores

version 3.1