A vulnerability was found in all versions of keycloak, where on using lower case HTTP headers (via cURL) we can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jetty). This means there is no protection when we put a Gatekeeper in front of a Jetty server and use lowercase headers.
References
| Link | Resource |
|---|---|
| https://issues.jboss.org/browse/KEYCLOAK-14090 | Issue Tracking Permissions Required Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1868591 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2021-02-23 13:15
Updated : 2021-06-22 15:45
NVD link : CVE-2020-14359
Mitre link : CVE-2020-14359
JSON object : View
Products Affected
redhat
- louketo_proxy
CWE
CWE-305
Authentication Bypass by Primary Weakness
