← Back

CVE-2020-27826

nvd nist
Published: May 28, 2021Modified: Jun 17, 2026

JSON object

Loading...
4.2
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.6 / Impact: 2.5
Source: NVD

Description

A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

Affected (4)

2 products
Keycloak
Single Sign On
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 12.0.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
All versions
Version 7.4.4
Version 7.4

References (2)

Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.