Back to search
CVE-2020-14389
Published: Nov 17, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
| Vendor | Product | Versions |
|---|---|---|
n/a | keycloak | affected before version 12.0.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now