CVE-2017-15111
keycloak-httpd-client-install: unsafe /tmp log file in --log-file option in keycloak_cli.py
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
keycloak-httpd-client-install, en versiones anteriores a la 0.8, crea archivos temporales de forma insegura, lo que permite que atacantes locales sobrescriban otros archivos mediante un enlace simbólico.
It was discovered that keycloak-httpd-client-install uses a predictable log file name in /tmp. A local attacker could create a symbolic link to a sensitive location, possibly causing data corruption or denial of service.
The keycloak-httpd-client-install packages provide various libraries and tools that can automate and simplify the configuration of Apache httpd authentication modules when registering as a Red Hat Single Sign-On federated Identity Provider client. Multiple unsafe actions have been addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-08 CVE Reserved
- 2018-01-20 CVE Published
- 2024-09-17 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- CWE-377: Insecure Temporary File
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/jdennis/keycloak-httpd-client-install/commit/07f26e213196936fb328ea0c1d5a66a09d8b5440 | 2019-08-06 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:2137 | 2019-08-06 | |
https://access.redhat.com/security/cve/CVE-2017-15111 | 2019-08-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1511623 | 2019-08-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Keycloak-httpd-client-install Project Search vendor "Keycloak-httpd-client-install Project" | Keycloak-httpd-client-install Search vendor "Keycloak-httpd-client-install Project" for product "Keycloak-httpd-client-install" | < 0.8 Search vendor "Keycloak-httpd-client-install Project" for product "Keycloak-httpd-client-install" and version " < 0.8" | - |
Affected
|