CVE-2020-14341 Information
Jun 07, 2022
cve
Description
The \Test Connection\ available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user’s choosing and originating from the RHSSO installation. By observing differences in the timings of these scans an attacker may glean information about hosts and ports which they do not have access to scan directly.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Reference
https://bugzilla.redhat.com/show_bug.cgi?id=1860138
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
2.7
Share on: