VulnerabilityModified
CVE-2021-3754
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user.
MEDIUM 5.3EPSS 2.15%
Does this matter?
Lower severity and a low EPSS score (2.15%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 2.15% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/keycloak · redhat/single sign-on
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2021-3754Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1999196Issue Tracking, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2021-3754Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1999196Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.