Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-778x-2mqv-w6xw

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью

Описание

Moderate severity vulnerability that affects org.keycloak:keycloak-core

Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 2.4.0

2.4.0

EPSS

Процентиль: 44%
0.00213
Низкий

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
redhat
почти 9 лет назад

Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.

CVSS3: 6.5
nvd
почти 8 лет назад

Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.

CVSS3: 6.5
debian
почти 8 лет назад

Red Hat Keycloak before version 2.4.0 did not correctly check permissi ...

EPSS

Процентиль: 44%
0.00213
Низкий

Дефекты

CWE-284