Description
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NExploitability: 1.2 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: High
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: None
Affected Packages5 packages
🔴Vulnerability Details
3OSVGeneration of Error Message Containing Sensitive Information in Keycloak↗2022-02-09 ▶ GHSAGeneration of Error Message Containing Sensitive Information in Keycloak↗2022-02-09 ▶ CVEListCVE-2020-1717: A flaw was found in Keycloak 7↗2021-02-11 ▶ 📋Vendor Advisories
1Red HatKeycloak: A logged in user can do an account email enumeration attack↗2021-02-10 ▶ 💬Community
2BugzillaCVE-2020-27760 ImageMagick: division by zero at MagickCore/enhance.c↗2020-11-03 ▶ BugzillaCVE-2020-1717 Keycloak: A logged in user can do an account email enumeration attack↗2020-01-30 ▶