Описание
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
Ссылки
- Vendor Advisory
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
EPSS
3.7 Low
CVSS3
Дефекты
Связанные уязвимости
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
A flaw was found in Keycloak. A remote attacker can exploit differenti ...
Keycloak's identity-first login flow exposes user information
EPSS
3.7 Low
CVSS3