CVE-2020-14389

HIGH

Keycloak <12.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

Scores

CVSS v3 8.1
EPSS 0.0015
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-916
Status published
Products (2)
org.keycloak/keycloak-core 0 - 12.0.0Maven
redhat/keycloak < 12.0.0
Published Nov 17, 2020
Tracked Since Feb 18, 2026