keycloak: adapter endpoints are exposed via arbitrary URLs
Published Jan 8, 2020
4.3
MEDIUMCVSS 3.1
EPSS 0.72%
Description
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Affected products
-
- Version fixed in 8.0.0StatusaffectedConstraints-
- Version
Configuration 2
- 7.3
Configuration 3
- 6.4.0
- 7.2.0
Configuration 4
- 7.0.0
No data.
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6
keycloak-adapter-sso7_3-eap6-0:4.8.13-1.Final_redhat_00001.1.ep6.el6
Fixed · RHSA-2019:3048
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7
keycloak-adapter-sso7_3-eap6-0:4.8.13-1.Final_redhat_00001.1.ep6.el7
Fixed · RHSA-2019:3048
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6
eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el6eap
Fixed · RHSA-2019:3049
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7
eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2019:3049
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8
eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2019:3049
Red Hat Single Sign-On 7.3 for RHEL 6
rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el6sso
Fixed · RHSA-2019:3044
Red Hat Single Sign-On 7.3 for RHEL 7
rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el7sso
Fixed · RHSA-2019:3045
Red Hat Single Sign-On 7.3 for RHEL 7
rh-sso7-libunix-dbus-java-0:0.8.0-2.el7sso
Fixed · RHSA-2019:3045
Red Hat Single Sign-On 7.3 for RHEL 8
rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el8sso
Fixed · RHSA-2019:3046
Red Hat Single Sign-On 7.3.4 zip
n/a
Fixed · RHSA-2019:3050
Text-Only RHOAR
n/a
Fixed · RHSA-2020:2067
Red Hat Fuse 7
keycloak
Not affected
Red Hat Mobile Application Platform 4
keycloak
Out of support scope
Red Hat OpenShift Application Runtimes
keycloak
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | keycloak-adapter-sso7_3-eap6-0:4.8.13-1.Final_redhat_00001.1.ep6.el6 | Fixed | RHSA-2019:3048 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 | keycloak-adapter-sso7_3-eap6-0:4.8.13-1.Final_redhat_00001.1.ep6.el7 | Fixed | RHSA-2019:3048 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el6eap | Fixed | RHSA-2019:3049 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2019:3049 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | eap7-keycloak-adapter-sso7_3-0:4.8.13-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2019:3049 |
| Red Hat Single Sign-On 7.3 for RHEL 6 | rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el6sso | Fixed | RHSA-2019:3044 |
| Red Hat Single Sign-On 7.3 for RHEL 7 | rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el7sso | Fixed | RHSA-2019:3045 |
| Red Hat Single Sign-On 7.3 for RHEL 7 | rh-sso7-libunix-dbus-java-0:0.8.0-2.el7sso | Fixed | RHSA-2019:3045 |
| Red Hat Single Sign-On 7.3 for RHEL 8 | rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el8sso | Fixed | RHSA-2019:3046 |
| Red Hat Single Sign-On 7.3.4 zip | n/a | Fixed | RHSA-2019:3050 |
| Text-Only RHOAR | n/a | Fixed | RHSA-2020:2067 |
| Red Hat Fuse 7 | keycloak | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | keycloak | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | keycloak | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
AV:N/AC:L/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.72% (0.00717) | 52.19th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.72% (0.00717) | 52.34th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.05% (0.00054) | 23.20th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.05% (0.00054) | 22.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00054) | 20.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.50% (0.04499) | 74.08th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.84% (0.01840) | 47.83th | v1 |
| Jan 6, 2022 | 1.84% (0.01840) | 47.32th | v1 |
| Jan 5, 2022 | 0.42% (0.00416) | 26.65th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (6)
- https://access.redhat.com/security/cve/CVE-2019-14820 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1649870 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14820 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-xfqh-7356-vqjj Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14820
- https://www.cve.org/CVERecord?id=CVE-2019-14820
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-14820 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1649870 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14820 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-xfqh-7356-vqjj | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-14820 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-14820 |
Change history (0)
No recorded changes yet.