[MAVEN:GHSA-MWM4-5QWR-G9PF] Keycloak is vulnerable to IDN homograph attack

Severity Low
Affected Packages 1
Fixed Packages 1

A flaw was found in keycloak, where IDN homograph attacks are possible. This flaw allows a malicious user to register a name that already exists and then tricking an admin to grant extra privileges. The highest threat from this vulnerability is to integrity.

Package Affected Version
pkg:maven/org.keycloak/keycloak-services < 18.0.0
Package Fixed Version
pkg:maven/org.keycloak/keycloak-services = 18.0.0
ID
MAVEN:GHSA-MWM4-5QWR-G9PF
Severity
low
URL
https://github.com/advisories/GHSA-mwm4-5qwr-g9pf
Published
2022-04-28T21:00:31
(2 years ago)
Modified
2023-01-07T05:00:40
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 18.0.0
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 18.0.0
Loading...