CVE Published: 07/01/2020 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: redhat |
Vendor: Red Hat |
Product: keycloak Status : PUBLISHED
CVE-2019-14837 Description
A flaw was found in keycloack before version 8.0.0. The owner of \'placeholder.org\' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name \'test\' the email address will be \'service-account-test@placeholder.org\'.