Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9695-w6h2-jpv9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.7

Описание

Keycloak users may be able to remove MFA from other users' devices

A community-only flaw was found where a malicious user can register himself and then uses the "remove devices" form to post different credential ids with the hope of removing MFA devices for other users.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

<= 9.0.1

9.0.2

EPSS

Процентиль: 47%
0.00238
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 4.1
redhat
почти 6 лет назад

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

CVSS3: 4.1
nvd
почти 6 лет назад

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

CVSS3: 4.1
debian
почти 6 лет назад

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in ...

EPSS

Процентиль: 47%
0.00238
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-285