CVE-2020-1728 PUBLISHED CVSS 4.800000190734863 MEDIUM

A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.

EPSS 0.13% · 32.9th percentile

Risk Scores

CVSS v3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.13%
32.9th percentile

Affected Products

VendorProductVersions
[UNKNOWN]keycloakn/a
redhatkeycloak0
quarkusquarkus0
Mavenorg.keycloak:keycloak-core0

Timeline

References

Open in Interactive Console →