REDHAT-BUG-1796281: Low severity Red Hat Keycloak vulnerability
Published Jan 30, 2020
·Updated
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
References: https://issues.jboss.org/browse/KEYCLOAK-12014
Affected Software
1 affected component
Red Hat Keycloak
Event History
Jan 30, 2020
Data Sourced
via Red Hat·05:31 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1796281?
The severity of REDHAT-BUG-1796281 is categorized as a medium level vulnerability.
2
How can I prevent REDHAT-BUG-1796281 email enumeration attacks?
To prevent REDHAT-BUG-1796281, implement account verification techniques and avoid disclosing specific account information in error messages.
3
Which version of Keycloak is affected by REDHAT-BUG-1796281?
Keycloak version 7.0.1 is affected by REDHAT-BUG-1796281.
4
What type of attack does REDHAT-BUG-1796281 allow?
REDHAT-BUG-1796281 allows a logged-in user to perform account email enumeration attacks.
5
Are there any known exploitations for REDHAT-BUG-1796281?
As of now, there are no widely reported exploitations specifically targeting REDHAT-BUG-1796281.