Bug 1860138 (CVE-2020-14341)

Summary: CVE-2020-14341 RHSSO: test connection function in console permits timing based port scanning
Product: [Other] Security Response Reporter: Dave Baker <dbaker>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: chazlett, crarobin, jmadigan, ngough, pdrozd, pjindal, psampaio, sthorger
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Red Hat Single Sign On. A test connection available on the application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing. By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly. The highest threat from this vulnerability is to data confidentiality.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1856175    

Description Dave Baker 2020-07-23 19:15:07 UTC
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation.

By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly.

Comment 5 Dave Baker 2020-07-24 14:15:39 UTC
Acknowledgments:

Name: Jeremy Choi (Red Hat Product Security)