7.5
CVSSv2

CVE-2020-14359

Published: 23/02/2021 Updated: 10/08/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jetty). This means there is no protection when we put a Gatekeeper in front of a Jetty server and use lowercase headers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat louketo proxy

Vendor Advisories

A vulnerability was found in keycloak, where on using lower case HTTP headers (via cURL) a Gatekeeper can be bypassed Lower case headers are also accepted by some webservers (eg Jetty) This means there is no protection when putting a Gatekeeper in front of a Jetty server and using lowercase headers ...