VDB
RHSA-2020%3A3017
RHSA-2020%3A3017
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in Keycloak, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Runtimes Spring Boot 2.1.15 |
Timeline
- Jul 27, 2020 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2020:3017 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=catRhoar.spring.boot&version=2.1.15 advisory
- https://access.redhat.com/documentation/en-us/red_hat_support_for_spring_boot/2.1/html-single/release_notes_for_spring_boot_2.1/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1705975 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1838332 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3017.json advisory
- https://access.redhat.com/security/cve/CVE-2020-1714 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1714 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1714 advisory
- https://access.redhat.com/security/cve/CVE-2020-9484 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-9484 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-9484 advisory
- http://mail-archives.apache.org/mod_mbox/tomcat-announce/202005.mbox/%3Ce3a0a517-bf82-ba62-0af6-24b83ea0e4e2%40apache.org%3E advisory
- http://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.0-M5 advisory
- http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.104 advisory
- http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.55 advisory
- http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.35 advisory