Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2017-0876.html | Third Party Advisory |
http://www.securityfocus.com/bid/97392 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038180 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2017:0872 | Vendor Advisory |
https://access.redhat.com/errata/RHSA-2017:0873 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1388988 | Issue Tracking |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2017-04-04T00:00:00
Updated: 2018-03-13T09:57:01
Reserved: 2016-10-12T00:00:00
Link: CVE-2016-8629
JSON object: View
NVD Information
Status : Modified
Published: 2018-03-12T15:29:00.210
Modified: 2019-10-09T23:20:06.460
Link: CVE-2016-8629
JSON object: View
Redhat Information
No data.