PT-2018-5037 · Red Hat · Red Hat Keycloak+1
Chess Hazlett
·
Publicado
2018-03-12
·
Atualizado
2019-10-09
·
CVE-2016-8629
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Keycloak versions prior to 2.4.0
Description
The issue arises from incorrect permission checks when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could exploit this to bypass normal permissions and delete users in a separate realm.
Recommendations
For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Keycloak
Red Hat Keycloak