CVE-2020-14389: High severity red hat keycloak vulnerability
A flaw was found in Keycloak, where it would permit a user with a view-profile role to manage the resources in the new account console. This flaw allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.
Other sources
A vulnerability was found in keycloak, where a user with only view-profile role is able to manage the resources in new account console.
References: https://issues.redhat.com/browse/KEYCLOAK-15295
— Red Hat
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-14389?
CVE-2020-14389 is a vulnerability found in Keycloak that allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.
What is the severity of CVE-2020-14389?
CVE-2020-14389 has a severity level of 8.1 (high).
How can I fix CVE-2020-14389?
To fix CVE-2020-14389, you should upgrade Keycloak to version 12.0.0 or higher.
Where can I find more information about CVE-2020-14389?
You can find more information about CVE-2020-14389 on the Red Hat website.
What is the CWE ID of CVE-2020-14389?
CVE-2020-14389 is associated with CWE ID 916.