CVE-2020-14389

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*

Information

Published : 2020-11-16 18:15

Updated : 2022-11-16 07:45


NVD link : CVE-2020-14389

Mitre link : CVE-2020-14389


JSON object : View

CWE
CWE-916

Use of Password Hash With Insufficient Computational Effort

Advertisement

dedicated server usa

Products Affected

redhat

  • keycloak