Skip to content

Keycloak is vulnerable to IDN homograph attack

Low
abstractj published GHSA-mwm4-5qwr-g9pf Apr 25, 2022

Package

maven org.keycloak.services (Maven)

Affected versions

< 18.0.0

Patched versions

18.0.0

Description

A flaw was found in keycloak, where IDN homograph attacks are possible. This flaw allows a malicious user to register a name that already exists and then tricking an admin to grant extra privileges. The highest threat from this vulnerability is to integrity.

Severity

Low

CVE ID

CVE-2021-3424

Weaknesses

Credits