CVE Vulnerabilities

CVE-2020-1718

Improper Authentication

Published: May 12, 2020 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Jboss_fuse Redhat 7.0.0 (including) 7.0.0 (including)
Keycloak Redhat * 8.0.0 (excluding)
Openshift_application_runtimes Redhat - (including) - (including)

Potential Mitigations

References