Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.1 Maven

keycloak vulnerable to unauthorized login via mail server setup

GHSA-cf8f-w2c5-p5jr · CVE-2019-14837

Published · Modified

Description

A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be 'service-account-test@placeholder.org'.

Ready to move

Start Securing

Free, no credit card | First findings in minutes