Spoofing attack in Keycloak - CVE-2021-3424
Published: May 25, 2021 / Updated: June 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user IDN names. A remote attacker can register with an IDN name, which looks exactly like a name of previously registered user and trick the application administrator into assigning higher privileges to such account.
Affected software
Red Hat Single Sign-On
rh-sso7-keycloak (Red Hat package)
How to mitigate CVE-2021-3424
Red Hat Single Sign-On - update to 7.4.7
rh-sso7-keycloak (Red Hat package) - addressed in versions 9.0.13-1.redhat_00006.1.el6sso, 9.0.13-1.redhat_00006.1.el7sso, 9.0.13-1.redhat_00006.1.el8sso