[MAVEN:GHSA-4VC8-PG5C-VG4X] Keycloak's improper input validation allows using email as username

Severity Low
Affected Packages 1
Fixed Packages 1

Keycloak allows the use of email as a username and doesn't check that an account with this email already exists. That could lead to the unability to reset/login with email for the user. This is caused by usernames being evaluated before emails.

Package Affected Version
pkg:maven/org.keycloak/keycloak-services < 24.0.1
Package Fixed Version
pkg:maven/org.keycloak/keycloak-services = 24.0.1
ID
MAVEN:GHSA-4VC8-PG5C-VG4X
Severity
low
URL
https://github.com/advisories/GHSA-4vc8-pg5c-vg4x
Published
2024-06-12T19:41:05
(3 months ago)
Modified
2024-06-12T19:41:06
(3 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 24.0.1
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 24.0.1
Loading...