CVE-2020-27826: Execution with Unnecessary Privileges
(updated )
A flaw was found in Keycloak where it is possible to update the user’s metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
References
Detect and mitigate CVE-2020-27826 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →