Keycloak Missing authentication for critical function
Moderate severity
GitHub Reviewed
Published
Mar 12, 2021
to the GitHub Advisory Database
•
Updated Sep 7, 2023
Description
Published by the National Vulnerability Database
Mar 9, 2021
Reviewed
Mar 12, 2021
Published to the GitHub Advisory Database
Mar 12, 2021
Last updated
Sep 7, 2023
A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
References