Incorrect Default Permissions Affecting rh-sso7-keycloak package, versions <0:18.0.16-1.redhat_00001.1.el8sso


Severity

Recommended
medium

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.65% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-RHSSO7KEYCLOAK-7925716
  • published10 Sept 2024
  • disclosed13 Jun 2024

Introduced: 13 Jun 2024

CVE-2024-5967  (opens in a new tab)
CWE-276  (opens in a new tab)

How to fix?

Upgrade RHEL:8 rh-sso7-keycloak to version 0:18.0.16-1.redhat_00001.1.el8sso or higher.
This issue was patched in RHSA-2024:6494.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rh-sso7-keycloak package and not the rh-sso7-keycloak package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL  independently without re-entering the currently configured LDAP bind credentials. This flaw allows an attacker with admin access (permission manage-realm) to change the LDAP host URL ("Connection URL") to a machine they control. The Keycloak server will connect to the attacker's host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console or compromised a user with sufficient privileges can leak domain credentials and attack the domain.

CVSS Base Scores

version 3.1