keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python2-keycloak-httpd-client-installUpgrade keycloak-httpd-client-install | Apr 27, 2020 | Jan 20, 2018 |
| Centos_linux | — | Upgrade keycloak-httpd-client-installUpgrade python2-keycloak-httpd-client-install | Aug 28, 2019 | Jan 20, 2018 |
| Oracle_linux | — | Upgrade python2-keycloak-httpd-client-installUpgrade keycloak-httpd-client-install | Aug 15, 2019 | Jan 5, 2018 |
| Redhat_linux | — | Upgrade python2-keycloak-httpd-client-installUpgrade keycloak-httpd-client-install | Aug 7, 2019 | Jan 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub