Vulnerability Description
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Keycloak Operator | < 8.0.2 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1731Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1731Issue TrackingThird Party Advisory
FAQ
What is CVE-2020-1731?
CVE-2020-1731 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password rem...
How severe is CVE-2020-1731?
CVE-2020-1731 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-1731?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Keycloak Operator.