CVE-2020-10686 MEDIUM

CVE-2020-10686

Vendor Keycloak
Product keycloak
Weakness CWE-285
Published May 4, 2020
Last update August 4, 2024

CVSS base score

4.1/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

Key dates

02Disclosure timeline

May 4, 2020 CVE published
August 4, 2024 Record updated