Improper privilege management in Keycloak
High severity
GitHub Reviewed
Published
Nov 10, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Nov 17, 2020
Reviewed
Nov 8, 2021
Published to the GitHub Advisory Database
Nov 10, 2021
Last updated
Feb 1, 2023
A flaw was found in Keycloak, where it would permit a user with a view-profile role to manage the resources in the new account console. This flaw allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.
References