A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2020-05-04T20:05:37

Updated: 2024-08-04T11:06:10.651Z

Reserved: 2020-03-20T00:00:00

Link: CVE-2020-10686

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-04T21:15:11.757

Modified: 2023-11-07T03:14:12.467

Link: CVE-2020-10686

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-04-29T00:00:00Z

Links: CVE-2020-10686 - Bugzilla