A flaw was found in Keycloak, where it would permit a user with a view-profile role to manage the resources in the new account console. This flaw allows a user with a view-profile role to access and modify data for which the user does not have adequate permission.
{ "nvd_published_at": "2020-11-17T02:15:00Z", "github_reviewed_at": "2021-11-08T18:54:51Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-269", "CWE-916" ] }