CVE-2020-1718: High severity red hat jboss fuse vulnerability
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
Other sources
A flaw was found in the reset credential flow in Keycloak. This flaw allows an attacker to gain unauthorized access to the application.
If the reset flow contains alternative subflow, it may be possible to connect to your application without credentials.
for more information : https://issues.redhat.com/browse/KEYCLOAK-11735
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-1718?
CVE-2020-1718 is a vulnerability found in Keycloak that allows an attacker to gain unauthorized access to the application.
What is the severity of CVE-2020-1718?
CVE-2020-1718 has a severity rating of 8.8 (high).
Which versions of Keycloak are affected by CVE-2020-1718?
All versions of Keycloak before 8.0.0 are affected by CVE-2020-1718.
What is the remedy for CVE-2020-1718?
Upgrade Keycloak to version 8.0.0 or later to fix the vulnerability.
Where can I find more information about CVE-2020-1718?
You can find more information about CVE-2020-1718 at the following references: [CVE-2020-1718](https://www.cve.org/CVERecord?id=CVE-2020-1718), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-1718), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1796756), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2020:3196).