CVE-2017-2582

MEDIUM

Redhat Keycloak < 2.5.1 - Information Disclosure

Title source: rule

Description

It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.

Scores

CVSS v3 6.5
EPSS 0.0063
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-201 CWE-200
Status published

Affected Products (6)

redhat/keycloak < 2.5.1
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
org.keycloak/keycloak-core < 2.5.1Maven

Timeline

Published Jul 26, 2018
Tracked Since Feb 18, 2026