CVE Vulnerabilities

CVE-2020-10686

Published: May 04, 2020 | Modified: Nov 07, 2023
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
4.1 MODERATE
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Ubuntu

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

Affected Software

Name Vendor Start Version End Version
Keycloak Redhat 8.0.2 (including) 8.0.2 (including)
Keycloak Redhat 9.0.0 (including) 9.0.0 (including)

References