Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10686

Опубликовано: 29 апр. 2020
Источник: redhat
CVSS3: 4.1

Описание

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

A flaw was found in Keycloak version 8.0.2 and 9.0.0, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7rh-sso7-keycloakNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1814609keycloak: remove other users MFA devices

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.1
nvd
почти 6 лет назад

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

CVSS3: 4.1
debian
почти 6 лет назад

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in ...

CVSS3: 4.7
github
больше 3 лет назад

Keycloak users may be able to remove MFA from other users' devices

4.1 Medium

CVSS3