
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in all versions of Keycloak Gatekeeper (CVE-2020-14359) that allows attackers to bypass the Gatekeeper protection mechanism when using lowercase HTTP headers. The vulnerability was reported on June 17, 2020, and particularly affects scenarios where Keycloak Gatekeeper is deployed in front of web servers that accept lowercase headers, such as Jetty (NVD, CVE Mitre).
The vulnerability stems from the Keycloak Gatekeeper's header processing mechanism, which fails to properly validate HTTP headers when they are sent in lowercase format, particularly when using tools like cURL. This oversight becomes particularly problematic when the Gatekeeper is placed in front of web servers like Jetty that accept lowercase headers, effectively nullifying the intended security protections (Red Hat Bugzilla).
When exploited, this vulnerability allows attackers to bypass the security controls implemented by Keycloak Gatekeeper, particularly when the system is configured with web servers that accept lowercase headers. This bypass could potentially lead to unauthorized access to protected resources (Debian Tracker).
The vulnerability can be exploited using tools like cURL by sending HTTP requests with lowercase headers to systems where Keycloak Gatekeeper is deployed in front of web servers that accept lowercase headers, such as Jetty (NVD).
The issue was tracked and addressed through Red Hat's security response system. Users are advised to check with their vendors for appropriate patches and updates (Red Hat Solution).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."