Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14389

Опубликовано: 04 нояб. 2020
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

A flaw was found in Keycloak, where it would permit a user with a view-profile role to manage the resources in the new account console. This flaw allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat support for Spring BootkeycloakNot affected
Red Hat Single Sign-On 7.4.3FixedRHSA-2020:493104.11.2020
Red Hat Single Sign-On 7.4 for RHEL 6rh-sso7-keycloakFixedRHSA-2020:492904.11.2020
Red Hat Single Sign-On 7.4 for RHEL 7rh-sso7-keycloakFixedRHSA-2020:493004.11.2020
Red Hat Single Sign-On 7.4 for RHEL 8rh-sso7-keycloakFixedRHSA-2020:493204.11.2020
Red Hat Single Sign-On 7.4 for RHEL 8rh-sso7-libunix-dbus-javaFixedRHSA-2020:493204.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-916
https://bugzilla.redhat.com/show_bug.cgi?id=1875843keycloak: user can manage resources with just "view-profile" role using new Account Console

EPSS

Процентиль: 36%
0.00148
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
около 5 лет назад

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

CVSS3: 8.1
debian
около 5 лет назад

It was found that Keycloak before version 12.0.0 would permit a user w ...

CVSS3: 8.1
github
около 4 лет назад

Improper privilege management in Keycloak

EPSS

Процентиль: 36%
0.00148
Низкий

8.1 High

CVSS3

Уязвимость CVE-2020-14389