CVE-2017-2582
This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
Does this matter?
Lower severity and a low EPSS score (2.46%). Track it; it rarely justifies an emergency change on its own.
Description
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.46% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-201, CWE-200
- Affected
- redhat/keycloak · redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/101046Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041707Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2808Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:2809Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:2810Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:2811Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3216Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3217Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3218Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3219Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3220Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2740Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2741Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2742Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2743Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0136
- https://access.redhat.com/errata/RHSA-2019:0137
- https://access.redhat.com/errata/RHSA-2019:0139
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2582Issue Tracking, Patch, Vendor Advisory
- https://github.com/keycloak/keycloak/pull/3715/commits/0cb5ba0f6e83162d221681f47b470c3042eef237Patch, Third Party Advisory
- http://www.securityfocus.com/bid/101046Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041707Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2808Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:2809Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:2810Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:2811Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3216Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3217Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3218Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3219Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.