CVE-2020-10686: Medium severity red hat keycloak vulnerability
A community-only flaw was found where a malicious user can register himself and then uses the "remove devices" form to post different credential ids with the hope of removing MFA devices for other users.
Other sources
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10686?
CVE-2020-10686 is a vulnerability found in Keycloak version 8.0.2 and 9.0.0, which allows a malicious user to register as oneself and potentially remove MFA devices for other users.
How severe is CVE-2020-10686?
CVE-2020-10686 has a severity rating of 4.7, which is considered medium.
How can I fix CVE-2020-10686 in Keycloak?
To fix CVE-2020-10686, you should upgrade Keycloak to version 9.0.1 or later.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-10686?
The CWE ID for CVE-2020-10686 is 285.
Where can I find more information about CVE-2020-10686?
More information about CVE-2020-10686 can be found at the following link: [CVE-2020-10686](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10686)