6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
6.1 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
33.2%
A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.
CPE | Name | Operator | Version |
---|---|---|---|
redhat:keycloak | redhat keycloak | eq | - |
[
{
"vendor": "redhat.com",
"product": "Keycloak",
"defaultStatus": "unaffected",
"versions": [
{
"version": "n/a",
"status": "unknown"
}
]
}
]
6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
6.1 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
33.2%