Lucene search

K
cvelistRedhatCVELIST:CVE-2023-0105
HistoryJan 11, 2023 - 8:46 p.m.

CVE-2023-0105

2023-01-1120:46:51
redhat
www.cve.org
2
cve-2023-0105
keycloak
email trust
impersonation
lockout

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.2%

A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.

CNA Affected

[
  {
    "vendor": "redhat.com",
    "product": "Keycloak",
    "defaultStatus": "unaffected",
    "versions": [
      {
        "version": "n/a",
        "status": "unknown"
      }
    ]
  }
]

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.2%