CVE-2020-1714
CVE-2020-1714
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 2.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 May 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Red Hat · keycloakWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →