You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It seems possible to get an access to another user's account because the plugin doesn't check verified flag provided by Discord. The procedure is as follows
Keycloak instance is installed, keycloak-discord plugin is added, the "Trust Email" option is off;
a user with known email already exists with and email is verified;
someone creates a new Discord account with the unverified email of the user mentioned above and uses it to log in to Keycloak;
the plugin trusts the email provided by Discord and merges the Discord login with the existing user;
the malicious person is authenticated as the user.
Can you verify the information above please?
The text was updated successfully, but these errors were encountered:
nalp
changed the title
The plugin doesn't check if email is verified or not
The plugin does not check whether the email is verified or not
May 10, 2024
It seems possible to get an access to another user's account because the plugin doesn't check
verified
flag provided by Discord. The procedure is as followsCan you verify the information above please?
The text was updated successfully, but these errors were encountered: