PoC Index

CVE-2021-3754

MEDIUM 5.3EPSS 2.4%

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v3.1
3.7 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
2.35% chance of exploitation in the next 30 days, 83th percentile
Published
2022-08-26
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related