Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9x9-xv66-xp3v

Опубликовано: 10 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Improper privilege management in Keycloak

A flaw was found in Keycloak, where it would permit a user with a view-profile role to manage the resources in the new account console. This flaw allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 12.0.0

12.0.0

EPSS

Процентиль: 36%
0.00148
Низкий

8.1 High

CVSS3

Дефекты

CWE-269
CWE-916

Связанные уязвимости

CVSS3: 8.1
redhat
больше 5 лет назад

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

CVSS3: 8.1
nvd
около 5 лет назад

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

CVSS3: 8.1
debian
около 5 лет назад

It was found that Keycloak before version 12.0.0 would permit a user w ...

EPSS

Процентиль: 36%
0.00148
Низкий

8.1 High

CVSS3

Дефекты

CWE-269
CWE-916