CVE-2020-10686
published 2020-05-04CVE-2020-10686: A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could…
PriorityP423medium4.7CVSS 3.1
AVNACLPRHUINSUCLILAL
EPSS
0.65%
47.5th percentile
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| keycloak | keycloak | — | — |
| keycloak | keycloak | — | — |
| redhat | keycloak | — | — |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: remove other users MFA devices
vendor_redhat·2020-04-29·CVSS 4.1
CVE-2020-10686 [MEDIUM] CWE-285 keycloak: remove other users MFA devices
keycloak: remove other users MFA devices
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.
A flaw was found in Keycloak version 8.0.2 and 9.0.0, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Not affected
OSV
Keycloak users may be able to remove MFA from other users' devices
osv·2022-05-24
CVE-2020-10686 [MEDIUM] Keycloak users may be able to remove MFA from other users' devices
Keycloak users may be able to remove MFA from other users' devices
A community-only flaw was found where a malicious user can register himself and then uses the "remove devices" form to post different credential ids with the hope of removing MFA devices for other users.
GHSA
Keycloak users may be able to remove MFA from other users' devices
ghsa·2022-05-24
CVE-2020-10686 [MEDIUM] CWE-285 Keycloak users may be able to remove MFA from other users' devices
Keycloak users may be able to remove MFA from other users' devices
A community-only flaw was found where a malicious user can register himself and then uses the "remove devices" form to post different credential ids with the hope of removing MFA devices for other users.
No detection rules found.
No public exploits indexed.
2020-05-04
Published