CVE-2020-10686

説明

A flaw was found in Keycloak version 8.0.2 and 9.0.0, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

CVSS (Common Vulnerability Scoring System) のスコアの詳細

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

以下の CSVV メトリクスおよびスコアは予備的で、再検討の対象となります。

CVSS v3 スコアの内訳

Red HatNVDcve.org
ベーススコア4.14.7N/A
攻撃ベクトルNetworkNetworkN/A
攻撃の複雑さHighLowN/A
必要な権限HighHighN/A
ユーザー関与レベルNoneNoneN/A
範囲UnchangedUnchangedN/A
機密性LowLowN/A
完全性への影響LowLowN/A
可用性への影響LowLowN/A

ベクトル

Red Hat: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

NVD: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

脆弱性の原因 (CWE) の理解

Confidentiality

Technical Impact: Read Application Data; Read Files or Directories

An attacker could read sensitive data, either by reading the data directly from a data store that is not properly restricted, or by accessing insufficiently-protected, privileged functionality to read the data.

Integrity

Technical Impact: Modify Application Data; Modify Files or Directories

An attacker could modify sensitive data, either by writing the data directly to a data store that is not properly restricted, or by accessing insufficiently-protected, privileged functionality to write the data.

Access Control

Technical Impact: Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands

When access control checks are not applied consistently - or not at all - an attacker could gain privileges and execute unauthorized code or commands by modifying or reading critical data directly, or by accessing insufficiently-protected, privileged functionality.

謝辞

Red Hat would like to thank Oliver P (SCISYS – now part of CGI) for reporting this issue.

よくある質問

エラータ通知の受信を希望しますか? こちらで登録してください