CVE-2020-1694
published 2020-09-16CVE-2020-1694: A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
1.64%
73.9th percentile
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 10.0.0 | 10.0.0 |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak
osv·2022-02-09
CVE-2020-1694 [MEDIUM] Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak
Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
GHSA
Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak
ghsa·2022-02-09
CVE-2020-1694 [MEDIUM] CWE-183 Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak
Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
Red Hat
keycloak: verify-token-audience support is missing in the NodeJS adapter
vendor_redhat·2020-07-02·CVSS 4.9
CVE-2020-1694 [MEDIUM] CWE-732 keycloak: verify-token-audience support is missing in the NodeJS adapter
keycloak: verify-token-audience support is missing in the NodeJS adapter
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
A flaw was found in Keycloak, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
Package: keycloak (Red Hat OpenShift Application Runtimes) - Not affected
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Affected
No detection rules found.
No public exploits indexed.
2020-09-16
Published