Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-14359
vulnerability analysis and mitigation

Overview

A vulnerability was discovered in all versions of Keycloak Gatekeeper (CVE-2020-14359) that allows attackers to bypass the Gatekeeper protection mechanism when using lowercase HTTP headers. The vulnerability was reported on June 17, 2020, and particularly affects scenarios where Keycloak Gatekeeper is deployed in front of web servers that accept lowercase headers, such as Jetty (NVD, CVE Mitre).

Technical details

The vulnerability stems from the Keycloak Gatekeeper's header processing mechanism, which fails to properly validate HTTP headers when they are sent in lowercase format, particularly when using tools like cURL. This oversight becomes particularly problematic when the Gatekeeper is placed in front of web servers like Jetty that accept lowercase headers, effectively nullifying the intended security protections (Red Hat Bugzilla).

Impact

When exploited, this vulnerability allows attackers to bypass the security controls implemented by Keycloak Gatekeeper, particularly when the system is configured with web servers that accept lowercase headers. This bypass could potentially lead to unauthorized access to protected resources (Debian Tracker).

Exploitability

The vulnerability can be exploited using tools like cURL by sending HTTP requests with lowercase headers to systems where Keycloak Gatekeeper is deployed in front of web servers that accept lowercase headers, such as Jetty (NVD).

Mitigation and workarounds

The issue was tracked and addressed through Red Hat's security response system. Users are advised to check with their vendors for appropriate patches and updates (Red Hat Solution).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management