CVE-2020-27826
published 2021-05-28CVE-2020-27826: A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an…
PriorityP421medium4.2CVSS 3.1
AVNACHPRLUINSUCLILAN
EPSS
0.57%
43.5th percentile
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 12.0.0 | 12.0.0 |
| redhat | keycloak | — | — |
| redhat | single_sign-on | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Authentication Bypass in keycloak
osv·2022-03-18
CVE-2020-27826 [HIGH] Authentication Bypass in keycloak
Authentication Bypass in keycloak
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
GHSA
Authentication Bypass in keycloak
ghsa·2022-03-18
CVE-2020-27826 [HIGH] CWE-250 Authentication Bypass in keycloak
Authentication Bypass in keycloak
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
Red Hat
keycloak: Account REST API can update user metadata attributes
vendor_redhat·2020-12-07·CVSS 4.2
CVE-2020-27826 [MEDIUM] CWE-250 keycloak: Account REST API can update user metadata attributes
keycloak: Account REST API can update user metadata attributes
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-28
Published