Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2020-27826

больше 5 лет назад

A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2020-27826

больше 5 лет назад

A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2020-27826

больше 5 лет назад

A flaw was found in Keycloak before version 12.0.0 where it is possibl ...

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-m9cj-v55f-8x26

больше 4 лет назад

Authentication Bypass in keycloak

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-27826

A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

CVSS3: 4.2
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-27826

A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

CVSS3: 4.2
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-27826

A flaw was found in Keycloak before version 12.0.0 where it is possibl ...

CVSS3: 4.2
1%
Низкий
больше 5 лет назад
github логотип
GHSA-m9cj-v55f-8x26

Authentication Bypass in keycloak

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу