Описание
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
Ссылки
- Vendor Advisory
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
EPSS
Процентиль: 24%
0.00318
Низкий
3.7 Low
CVSS3
Дефекты
CWE-209
Связанные уязвимости
CVSS3: 3.7
redhat
больше 1 года назад
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
CVSS3: 3.7
debian
5 месяцев назад
A flaw was found in Keycloak. A remote attacker can exploit differenti ...
CVSS3: 3.7
github
5 месяцев назад
Keycloak's identity-first login flow exposes user information
EPSS
Процентиль: 24%
0.00318
Низкий
3.7 Low
CVSS3
Дефекты
CWE-209