Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3754

Опубликовано: 26 авг. 2022
Источник: debian
EPSS Средний

Описание

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 93%
0.11083
Средний

Связанные уязвимости

CVSS3: 3.7
redhat
больше 3 лет назад

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

CVSS3: 5.3
nvd
больше 3 лет назад

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

CVSS3: 3.7
github
больше 1 года назад

Keycloak's improper input validation allows using email as username

EPSS

Процентиль: 93%
0.11083
Средний