Improper authorization control for web services In org.keycloak:keycloak-services
Description
Keycloak is vulnerable to IDN homograph attack A flaw was found in keycloak, where IDN homograph attacks are possible. This flaw allows a malicious user to register a name that already exists and then tricking an admin to grant extra privileges. The highest threat from this vulnerability is to integrity.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 18.0.0 |
Aliases
1. 2.
References
1. 2.