CVE-2019-14837
published 2020-01-07CVE-2019-14837: A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a…
PriorityP346critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.72%
74.9th percentile
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be '[email protected]'.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | < 8.0.0 | 8.0.0 |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure
vendor_redhat·2019-12-02·CVSS 9.1
CVE-2019-14837 [CRITICAL] CWE-547 keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure
keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be '[email protected]'.
A flaw was found in Keycloak. The use of an open hard-coded domain can allow an unauthorized login by setting up a mail server and resetting the user credentials, enabling information disclosure.
Mitigation: It is not a very straight forward workaround but it is possible to mitigate this by manually editing the default Email ID ([email protected]) to some valid email ID (abc@
OSV
keycloak vulnerable to unauthorized login via mail server setup
osv·2022-05-24
CVE-2019-14837 [CRITICAL] keycloak vulnerable to unauthorized login via mail server setup
keycloak vulnerable to unauthorized login via mail server setup
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be '[email protected]'.
GHSA
keycloak vulnerable to unauthorized login via mail server setup
ghsa·2022-05-24
CVE-2019-14837 [CRITICAL] CWE-547 keycloak vulnerable to unauthorized login via mail server setup
keycloak vulnerable to unauthorized login via mail server setup
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be '[email protected]'.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14837 keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure
bugzilla·2019-07-16·CVSS 9.1
CVE-2019-14837 [CRITICAL] CVE-2019-14837 keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure
CVE-2019-14837 keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be '[email protected]'
Upstream issue:
https://issues.jboss.org/browse/KEYCLOAK-10780
Upstream patch:
https://github.com/keycloak/keycloak/commit/9a7c1a91a59ab85e7f8889a505be04a71580777f
Discussion:
The version of Keycloak used in Red Hat Mobile Application Platform did not have the Service Account feature. It was added in version 1.4, see: https://planet.jboss.org/post/service_accounts_support_in_k
arXiv
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
arxiv_fulltext·2025-06-11
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
: Is Your "Clean" Vulnerability Dataset Really Solvable?
Exposing and Trapping Undecidable Patches and Beyond
@IEEEauthorhalign
@IEEEauthorhalign
Zeyu Gao1 1Equal contribution
Tsinghua University
[email protected]
Junlin Zhou1
Sichuan University
[email protected]
Bolun Zhang
Institute of Information Engineering,
Chinese Academy of Sciences
[email protected]
Yi He
Wuhan University
[email protected]
Chao Zhang22Corresponding author
Tsinghua University
[email protected]
Yuxin Cui
Tsinghua University
[email protected]
Hao Wang
Tsinghua University
[email protected]
## Abstract
The quantity and quality of vulnerability datasets are essential for developing deep learning solutions to vulnerability-related tasks. Due
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14837https://github.com/keycloak/keycloak/commit/9a7c1a91a59ab85e7f8889a505be04a71580777fhttps://issues.jboss.org/browse/KEYCLOAK-10780https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14837https://github.com/keycloak/keycloak/commit/9a7c1a91a59ab85e7f8889a505be04a71580777fhttps://issues.jboss.org/browse/KEYCLOAK-10780
2020-01-07
Published