Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10686

Опубликовано: 04 мая 2020
Источник: nvd
CVSS3: 4.1
CVSS3: 4.7
CVSS2: 6.5
EPSS Низкий

Описание

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:keycloak:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:keycloak:9.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00238
Низкий

4.1 Medium

CVSS3

4.7 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.1
redhat
почти 6 лет назад

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

CVSS3: 4.1
debian
почти 6 лет назад

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in ...

CVSS3: 4.7
github
больше 3 лет назад

Keycloak users may be able to remove MFA from other users' devices

EPSS

Процентиль: 47%
0.00238
Низкий

4.1 Medium

CVSS3

4.7 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-Other