Bug 1796281 (CVE-2020-1717) - CVE-2020-1717 Keycloak: A logged in user can do an account email enumeration attack
Summary: CVE-2020-1717 Keycloak: A logged in user can do an account email enumeration ...
Keywords:
Status: NEW
Alias: CVE-2020-1717
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1771890
TreeView+ depends on / blocked
 
Reported: 2020-01-30 05:31 UTC by Paramvir jindal
Modified: 2023-07-07 08:34 UTC (History)
19 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in keycloak. An attacker could use the change email function in the account settings to determine if an email address was already used for another account (an account enumeration attack). The highest threat from this flaw is to data confidentiality.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Paramvir jindal 2020-01-30 05:31:15 UTC
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. 

References: 
 
https://issues.jboss.org/browse/KEYCLOAK-12014

Comment 2 Paramvir jindal 2020-01-30 05:36:45 UTC
Marking RHSSO 7 as affected.

Comment 7 Eric Christensen 2021-02-16 20:31:02 UTC
External References:

https://issues.redhat.com/browse/KEYCLOAK-12014


Note You need to log in before you can comment on or make changes to this bug.