{"id":"GHSA-mwm4-5qwr-g9pf","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mwm4-5qwr-g9pf","summary":"Keycloak is vulnerable to IDN homograph attack","details":"A flaw was found in keycloak, where IDN homograph attacks are possible. This flaw allows a malicious user to register a name that already exists and then tricking an admin to grant extra privileges. The highest threat from this vulnerability is to integrity.","published":"2022-04-28T21:00:31Z","modified":"2024-11-28T05:41:12.609673Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.keycloak:keycloak-services","fixedVersion":"18.0.0"}],"fix":{"url":"https://github.com/keycloak/keycloak/commit/ac79fd0c23c6947a04073afc61e30d341498438e","label":"keycloak/keycloak@ac79fd0"},"references":[{"type":"WEB","url":"https://github.com/keycloak/keycloak/security/advisories/GHSA-mwm4-5qwr-g9pf"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/commit/ac79fd0c23c6947a04073afc61e30d341498438e"},{"type":"PACKAGE","url":"https://github.com/keycloak/keycloak"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:41:12.609673Z"}}