A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1183 A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
Github GHSA Github GHSA GHSA-rvfc-g8j5-9ccf Generation of Error Message Containing Sensitive Information in Keycloak
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T06:46:29.996Z

Reserved: 2019-11-27T00:00:00

Link: CVE-2020-1717

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-11T18:15:14.317

Modified: 2024-11-21T05:11:13.880

Link: CVE-2020-1717

cve-icon Redhat

Severity : Low

Publid Date: 2021-02-10T00:00:00Z

Links: CVE-2020-1717 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses