ZeroHour

CVE-2020-10686

CVSS 3.1
4.7 medium
EPSS
<1%p49
Published
()
Modified
Description

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

Vendors
redhat
Products
keycloak
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.