Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38931
HistoryJan 20, 2023 - 1:24 a.m.

Insecure Permissions

2023-01-2001:24:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
insecure permissions
email trust
shadowing users
impersonation
lockout

0.001 Low

EPSS

Percentile

33.2%

org.keycloak:keycloak-parent is vulnerable to Insecure Permissions. An attacker is able to shadow other users with the same email and impersonate or lockout the victim due to the email trust not being handled correctly.

CPENameOperatorVersion
keycloakle20.0.3
keycloakle20.0.3

0.001 Low

EPSS

Percentile

33.2%