PT-2021-13862 · Red Hat · Keycloak
Paramvir Jindal
+1
·
Published
2021-03-09
·
Updated
2021-03-15
·
CVE-2021-20262
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Keycloak version 12.0.0
Description:
A flaw was found in Keycloak where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Recommendations:
For Keycloak version 12.0.0, consider implementing additional authentication measures to prevent account takeover, such as requiring re-authentication before password updates. As a temporary workaround, restrict access to password update functionality until a patch is available.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak