CRITICAL 9.1 Maven

keycloak vulnerable to unauthorized login via mail server setup

GHSA-cf8f-w2c5-p5jr · CVE-2019-14837

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be 'service-account-test@placeholder.org'.

Ready to move

Start Securing

Free, no credit card | First findings in minutes