AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2020-27838

MEDIUM · CVSS 6.5 EPSS 17.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-03-08 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. Its EPSS score suggests a 17.9% probability of exploitation in the next 30 days.

CVE
CVE-2020-27838
Severity
MEDIUM
CVSS
6.5
EPSS
17.94%

Original NVD Description

A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.

Related CVEs

Other vulnerabilities affecting the same vendor(s)