[MAVEN:GHSA-MWM4-5QWR-G9PF] Keycloak is vulnerable to IDN homograph attack
Severity
Low
Affected Packages
1
Fixed Packages
1
A flaw was found in keycloak, where IDN homograph attacks are possible. This flaw allows a malicious user to register a name that already exists and then tricking an admin to grant extra privileges. The highest threat from this vulnerability is to integrity.
Package | Affected Version |
---|---|
pkg:maven/org.keycloak/keycloak-services | < 18.0.0 |
Package | Fixed Version |
---|---|
pkg:maven/org.keycloak/keycloak-services | = 18.0.0 |
- ID
- MAVEN:GHSA-MWM4-5QWR-G9PF
- Severity
- low
- URL
- https://github.com/advisories/GHSA-mwm4-5qwr-g9pf
- Published
-
2022-04-28T21:00:31
(2 years ago) - Modified
-
2023-01-07T05:00:40
(20 months ago) - Rights
- Maven Security Team
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:maven/org.keycloak/keycloak-services | org.keycloak | keycloak-services | < 18.0.0 | |||
Fixed | pkg:maven/org.keycloak/keycloak-services | org.keycloak | keycloak-services | = 18.0.0 |