CVE-2020-1714 PUBLISHED CVSS 7.5 HIGH

Reported by redhat · Published May 13, 2020

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatkeycloakbefore 11.0.0
Mavenorg.keycloak:keycloak-parent
Mavenorg.keycloak:keycloak-common0, 0, 0
Mavenorg.keycloak:keycloak-core0, 0, 0
Red Hatkeycloakbefore 11.0.0, before 11.0.0, before 11.0.0

Timeline

References

Open in Interactive Console →