Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7xw-p58w-h6fj

Опубликовано: 18 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Keycloak: Impersonation and lockout possible through incorrect handling of email trust

Impersonation and lockout are possible due to email trust not being handled correctly in Keycloak. Since the verified state is not reset when the email changes, it is possible for users to shadow others with the same email and lock out or impersonate them.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 22.0.1

22.0.1

EPSS

Процентиль: 42%
0.00203
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-841

Связанные уязвимости

CVSS3: 6.3
redhat
около 3 лет назад

A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.

CVSS3: 6.5
nvd
около 3 лет назад

A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.

CVSS3: 6.5
debian
около 3 лет назад

A flaw was found in Keycloak. This flaw allows impersonation and locko ...

EPSS

Процентиль: 42%
0.00203
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-841