First published: Mon May 04 2020(Updated: )
A community-only flaw was found where a malicious user can register himself and then uses the "remove devices" form to post different credential ids with the hope of removing MFA devices for other users.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Keycloak | =8.0.2 | |
Redhat Keycloak | =9.0.0 | |
maven/org.keycloak:keycloak-core | <=9.0.1 | 9.0.2 |
=8.0.2 | ||
=9.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10686 is a vulnerability found in Keycloak version 8.0.2 and 9.0.0, which allows a malicious user to register as oneself and potentially remove MFA devices for other users.
CVE-2020-10686 has a severity rating of 4.7, which is considered medium.
To fix CVE-2020-10686, you should upgrade Keycloak to version 9.0.1 or later.
The CWE ID for CVE-2020-10686 is 285.
More information about CVE-2020-10686 can be found at the following link: [CVE-2020-10686](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10686)