PT-2022-10657 · Red Hat · Keycloak

Michael Kaplan

·

Published

2022-08-26

·

Updated

2024-06-12

·

CVE-2021-3754

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw was found in Keycloak where an attacker can register with a username that is the same as an existing user's email ID. This may cause issues with password recovery emails if the user forgets their password. The problem arises because Keycloak allows the use of email as a username and does not check if an account with that email already exists, leading to potential difficulties in resetting or logging in with the email for the affected user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3754
GHSA-4VC8-PG5C-VG4X
GHSA-J9XQ-J329-2XVG

Affected Products

Keycloak