Skip to content

Improper Restriction of Rendered UI Layers or Frames in Keycloak

Moderate severity GitHub Reviewed Published Apr 15, 2020 to the GitHub Advisory Database • Updated Feb 1, 2023

Package

maven org.keycloak:keycloak-core (Maven)

Affected versions

<= 9.0.3

Patched versions

None

Description

A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.

References

Published by the National Vulnerability Database Apr 6, 2020
Reviewed Apr 15, 2020
Published to the GitHub Advisory Database Apr 15, 2020
Last updated Feb 1, 2023

Severity

Moderate

Weaknesses

CVE ID

CVE-2020-1728

GHSA ID

GHSA-3gg7-9q2x-79fc

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.