Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3424

Опубликовано: 08 мар. 2021
Источник: redhat
CVSS3: 5.3

Описание

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.

A flaw was found in keycloak, where IDN homograph attacks are possible. This flaw allows a malicious user to register a name that already exists and then tricking an admin to grant extra privileges. The highest threat from this vulnerability is to integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat Integration Camel K 1keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat support for Spring BootkeycloakNot affected
Red Hat Single Sign-On 7.4.7FixedRHSA-2021:207020.05.2021
Red Hat Single Sign-On 7.4 for RHEL 6rh-sso7-keycloakFixedRHSA-2021:206320.05.2021
Red Hat Single Sign-On 7.4 for RHEL 7rh-sso7-keycloakFixedRHSA-2021:206420.05.2021
Red Hat Single Sign-On 7.4 for RHEL 8rh-sso7-keycloakFixedRHSA-2021:206520.05.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1933320keycloak: Internationalized domain name (IDN) homograph attack to impersonate users

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.

CVSS3: 5.3
debian
больше 4 лет назад

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 ...

CVSS3: 5.3
github
почти 4 года назад

Keycloak is vulnerable to IDN homograph attack

5.3 Medium

CVSS3