Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vc8-pg5c-vg4x

Опубликовано: 12 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Keycloak's improper input validation allows using email as username

Keycloak allows the use of email as a username and doesn't check that an account with this email already exists. That could lead to the unability to reset/login with email for the user. This is caused by usernames being evaluated before emails.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 24.0.1

24.0.1

EPSS

Процентиль: 94%
0.12319
Средний

3.7 Low

CVSS3

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 3.7
redhat
больше 3 лет назад

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

CVSS3: 5.3
nvd
больше 3 лет назад

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

CVSS3: 5.3
debian
больше 3 лет назад

A flaw was found in keycloak where an attacker is able to register him ...

EPSS

Процентиль: 94%
0.12319
Средний

3.7 Low

CVSS3

Дефекты

CWE-670