FlawAtlas
Search the atlas
CVE-2023-0105 Moderate

Keycloak: Impersonation and lockout possible through incorrect handling of email trust

Impersonation and lockout are possible due to email trust not being handled correctly in Keycloak. Since the verified state is not reset when the email changes, it is possible for users to shadow others with the same email and lock out or impersonate them.

Exploit probability 0.7%
Published July 18, 2023
Required by Not available
Last source change February 16, 2024

02 / AFFECTED SOFTWARE

Affected packages

Maven org.keycloak:keycloak-core

155 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-c7xw-p58w-h6fj

Impersonation and lockout are possible due to email trust not being handled correctly in Keycloak. Since the verified state is not reset when the email changes, it is possible for users to shadow others with the same email and lock out or impersonate them.

View original source

05 / REFERENCES

Further evidence