CVE-2021-3754
published 2022-08-26CVE-2021-3754: A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.84%
76.5th percentile
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: allows using email as username
vendor_redhat·2022-05-30·CVSS 5.3
CVE-2021-3754 [MEDIUM] CWE-20 keycloak: allows using email as username
keycloak: allows using email as username
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
Mitigation: The workaround is to enable "Email as username" flag or disable "Login with email" in the login settings
Package: keycloak (Red Hat Decision Manager 7) - Not affected
Package: keycloak (Red Hat OpenShift Application Runtimes) - Not affected
Package: keycloak (Red Hat Process
OSV
Keycloak's improper input validation allows using email as username
osv·2024-06-12
CVE-2021-3754 [LOW] Keycloak's improper input validation allows using email as username
Keycloak's improper input validation allows using email as username
Keycloak allows the use of email as a username and doesn't check that an account with this email already exists. That could lead to the unability to reset/login with email for the user. This is caused by usernames being evaluated before emails.
GHSA
Keycloak's improper input validation allows using email as username
ghsa·2024-06-12
CVE-2021-3754 [LOW] CWE-670 Keycloak's improper input validation allows using email as username
Keycloak's improper input validation allows using email as username
Keycloak allows the use of email as a username and doesn't check that an account with this email already exists. That could lead to the unability to reset/login with email for the user. This is caused by usernames being evaluated before emails.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-26
Published