Related Vulnerabilities: CVE-2020-27826  

A flaw was found in keycloak versions prior to 12.0.0 where it is possible to update the user's meta-data attributes using Account REST API. It is now possible for any evil user to change its own NameID attribute to impersonate the admin user for any particular application.

Severity Medium

Remote Yes

Type Privilege escalation

Description

A flaw was found in keycloak versions prior to 12.0.0 where it is possible to update the user's meta-data attributes using Account REST API. It is now possible for any evil user to change its own NameID attribute to impersonate the admin user for any particular application.

AVG-1332 keycloak 11.0.3-1 Medium Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1905089