GHSA-4vc8-pg5c-vg4x
Dashboard / Vulnerabilities / GHSA-4vc8-pg5c-vg4x
Summary: Keycloak's improper input validation allows using email as username
Details: Keycloak allows the use of email as a username and doesn't check that an account with this email already exists. That could lead to the unability to reset/login with email for the user. This is caused by usernames being evaluated before emails.
References: https://github.com/keycloak/keycloak/security/advisories/GHSA-4vc8-pg5c-vg4x, https://nvd.nist.gov/vuln/detail/CVE-2021-3754, https://github.com/keycloak/keycloak/commit/f9708037383aa98741e4850447de64dc4a0d4b4e, https://access.redhat.com/security/cve/CVE-2021-3754, https://bugzilla.redhat.com/show_bug.cgi?id=1999196, https://github.com/keycloak/keycloak
Affected packages
Package
Name: org.keycloak:keycloak-services
Purl: pkg:maven/org.keycloak/keycloak-services
Affected ranges
Type: ECOSYSTEM
Events:
