Keycloak vulnerable to phishing attacks through its Review Profile section
Moderate severity
GitHub Reviewed
Published
Jul 10, 2025
to the GitHub Advisory Database
•
Updated Jul 10, 2025
Description
Published by the National Vulnerability Database
Jul 10, 2025
Published to the GitHub Advisory Database
Jul 10, 2025
Reviewed
Jul 10, 2025
Last updated
Jul 10, 2025
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's account, triggering a verification email sent to the victim's email address. The attacker's email address is not present in the verification email content, making it a potential phishing opportunity. If the victim clicks the verification link, the attacker can gain access to the victim's account.
References