Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pf38-cw3p-22q9

Опубликовано: 28 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Keycloak is vulnerable to IDN homograph attack

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 18.0.0

18.0.0

EPSS

Процентиль: 37%
0.00164
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.3
redhat
почти 5 лет назад

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.

CVSS3: 5.3
nvd
больше 4 лет назад

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.

CVSS3: 5.3
debian
больше 4 лет назад

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 ...

EPSS

Процентиль: 37%
0.00164
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287