Back

CRITICAL

keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure

Published Jan 7, 2020

Description

A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be 'service-account-test@placeholder.org'.

Affected products

Remediation

Red Hat mitigation

It is not a very straight forward workaround but it is possible to mitigate this by manually editing the default Email ID (service_account_name@placeholder.org) to some valid email ID (abc@gmail.com) in the USER_ENTITY table in the RHSSO database used.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 7, 2020
Updated Aug 5, 2024
Reserved Aug 10, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 2, 2019
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a
GHSA-CF8F-W2C5-P5JR