Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 Maven

Keycloak is vulnerable to IDN homograph attack

GHSA-pf38-cw3p-22q9 · CVE-2021-3424

Published · Modified

Description

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.

Ready to move

Start Securing

Free, no credit card | First findings in minutes