Description
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4vc8-pg5c-vg4x | Keycloak's improper input validation allows using email as username |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:09:08.286Z
Reserved: 2021-08-31T00:00:00.000Z
Link: CVE-2021-3754
No data.
Status : Modified
Published: 2022-08-26T16:15:09.520
Modified: 2024-11-21T06:22:20.783
Link: CVE-2021-3754
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA