Spoofing attack in Keycloak - CVE-2021-3424
Published: May 25, 2021 / Updated: May 25, 2021
Keycloak
Keycloak
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user IDN names. A remote attacker can register with an IDN name, which looks exactly like a name of previously registered user and trick the application administrator into assigning higher privileges to such account.