First published: Fri Sep 04 2020(Updated: )
A flaw was found in Keycloak, where it would permit a user with a view-profile role to manage the resources in the new account console. This flaw allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/keycloak | <12.0.0 | 12.0.0 |
redhat/rh-sso7-keycloak | <0:9.0.9-1.redhat_00001.1.el6 | 0:9.0.9-1.redhat_00001.1.el6 |
redhat/rh-sso7-keycloak | <0:9.0.9-1.redhat_00001.1.el7 | 0:9.0.9-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:9.0.9-1.redhat_00001.1.el8 | 0:9.0.9-1.redhat_00001.1.el8 |
redhat/rh-sso7-libunix-dbus-java | <0:0.8.0-2.el8 | 0:0.8.0-2.el8 |
Redhat Keycloak | <12.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-14389 is a vulnerability found in Keycloak that allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.
CVE-2020-14389 has a severity level of 8.1 (high).
To fix CVE-2020-14389, you should upgrade Keycloak to version 12.0.0 or higher.
You can find more information about CVE-2020-14389 on the Red Hat website.
CVE-2020-14389 is associated with CWE ID 916.