Hide Forgot
A community-only flaw was found where a malicious user can registers himself and then uses the remove devices form to post different credential ids with the hope of removing MFA devices for other users. https://issues.jboss.org/browse/KEYCLOAK-13259
requesting CVE for this community-only flaw.
Acknowledgments: Name: Oliver P (SCISYS – now part of CGI)