5l1D3R / Github-actions

0 stars 0 forks source link

CVE: 2017-2582 found in Keycloak SAML Core - Version: 1.8.1.Final [JAVA] #24

Open github-actions[bot] opened 1 year ago

github-actions[bot] commented 1 year ago

Veracode Software Composition Analysis

Attribute Details
Library Keycloak SAML Core
Description Keycloak SSO
Language JAVA
Vulnerability Information Disclosure
Vulnerability description keycloak-saml-core is vulnerable to sensitive information disclosure. The attack exists because SAML messages are being parsed by replacing the string to obtain the attribute values with the system property in StaxParserUtil class. Therefore, attacker can just parse the chosen system property name through the SAML request ID field and can get the response with system property value in InResponseTo filed .
CVE 2017-2582
CVSS score 4
Vulnerability present in version/s 1.2.0.CR1-2.5.0.Final
Found library version/s 1.8.1.Final
Vulnerability fixed in version 2.5.1.Final
Library latest version 20.0.1
Fix

Links:

github-actions[bot] commented 1 year ago

Veracode issue link to PR: https://github.com/5l1D3R/Github-actions/pull/2