PT-2018-5037 · Red Hat · Red Hat Keycloak+1

Chess Hazlett

·

Publicado

2018-03-12

·

Atualizado

2019-10-09

·

CVE-2016-8629

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Keycloak versions prior to 2.4.0
Description The issue arises from incorrect permission checks when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could exploit this to bypass normal permissions and delete users in a separate realm.
Recommendations For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8629
GHSA-778X-2MQV-W6XW
RHSA-2017:0872
RHSA-2017:0873

Produtos afetados

Keycloak
Red Hat Keycloak