What the vulnerability does

01Description

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

Key dates

02Disclosure timeline

November 17, 2020 CVE published
August 4, 2024 Record updated