Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-14389

Опубликовано: 17 нояб. 2020
Источник: debian
EPSS Низкий

Описание

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 36%
0.00148
Низкий

Связанные уязвимости

CVSS3: 8.1
redhat
больше 5 лет назад

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

CVSS3: 8.1
nvd
около 5 лет назад

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

CVSS3: 8.1
github
около 4 лет назад

Improper privilege management in Keycloak

EPSS

Процентиль: 36%
0.00148
Низкий