CVE-2017-2582
MEDIUMRedhat Keycloak < 2.5.1 - Information Disclosure
Title source: ruleDescription
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
References (20)
Scores
CVSS v3
6.5
EPSS
0.0063
EPSS Percentile
69.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-201
CWE-200
Status
published
Affected Products (6)
redhat/keycloak
< 2.5.1
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
org.keycloak/keycloak-core
< 2.5.1Maven
Timeline
Published
Jul 26, 2018
Tracked Since
Feb 18, 2026