User Registration Vulnerability in Keycloak by Red Hat
CVE-2020-10686
4.1MEDIUM
What is CVE-2020-10686?
A vulnerability in Keycloak versions 8.0.2 and 9.0.0 enables an attacker to register as another user. This exploitation allows the malicious actor to utilize the remove devices form to submit various credential IDs, potentially allowing them to remove multi-factor authentication (MFA) devices belonging to different users, thereby compromising their security.
Affected Version(s)
keycloak 8.0.2
keycloak 9.0.0
