6.8
CVSSv3

CVE-2021-20262

CVSSv4: NA | CVSSv3: 6.8 | CVSSv2: 4.6 | VMScore: 780 | EPSS: 0.00044 | KEV: Not Included
Published: 09/03/2021 Updated: 21/11/2024

Vulnerability Summary

A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an malicious user to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat keycloak 12.0.0

redhat single sign-on 7.0

Vendor Advisories

A security issue was found in Keycloak where re-authentication does not occur while updating the password This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2020-1695, CVE-2020-1723, CVE-2020-1725, CVE-2020-10770, CVE-2020-14302, CVE-2020-15522, CVE-2020-25711, CVE-2020-27838, CVE-2020-28052, CVE-2020-28491, CVE-2021-3424, CVE-2021-3712, CVE-2021-20195, CVE-2021-20202, CVE-2021-20222, CVE-2021-20262, CVE-2021-21290, C ...