It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
References
Configurations
History
21 Nov 2024, 05:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1875843%2C - |
07 Nov 2023, 03:17
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-11-17 02:15
Updated : 2024-11-21 05:03
NVD link : CVE-2020-14389
Mitre link : CVE-2020-14389
CVE.ORG link : CVE-2020-14389
JSON object : View
Products Affected
redhat
- keycloak
CWE
CWE-916
Use of Password Hash With Insufficient Computational Effort