StackRadar

CVE-2023-0105

Medium

Advisory

Published 18 Jul 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
1 of 1
affected package

Keycloak: Impersonation and lockout possible through incorrect handling of email trust

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
keycloak-coremaven3.4.0.Final, 12.0.4, 13.0.1, 14.0.0+7 more22.0.112
OSV records
GHSA-c7xw-p58w-h6fj

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
keycloak-core@17.0.1
22.0.1

Open the chart page →

7,713
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
keycloak-core@3.4.0.Final
22.0.1

Open the chart page →

10,732
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
keycloak-core@20.0.5
22.0.1

Open the chart page →

37,373
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
keycloak-core@13.0.1
22.0.1

Open the chart page →

3,958
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
keycloak-core@17.0.1
22.0.1

Open the chart page →

7,713
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
keycloak-core@19.0.3
22.0.1

Open the chart page →

13,352
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
keycloak-core@20.0.5
22.0.1

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
keycloak-core@20.0.5
22.0.1

Open the chart page →

6,915
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
keycloak-core@18.0.2
22.0.1

Open the chart page →

34,754
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
keycloak-core@19.0.1
22.0.1

Open the chart page →

5,875
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
keycloak-core@20.0.1
22.0.1

Open the chart page →

6,443
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
keycloak-core@12.0.4
22.0.1

Open the chart page →

12,455
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
keycloak-core@14.0.0
22.0.1

Open the chart page →

28,605
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-0105.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
keycloak-core@20.0.3
22.0.1

Open the chart page →

6,016

Container images carrying it

12 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:20.0054ef67eb7da
keycloak-core@20.0.5
22.0.1
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
keycloak-core@17.0.1
22.0.1
2
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
keycloak-core@12.0.4
22.0.1
1
assistiot/identity-manager_kc:latest0df4b4fa899a
keycloak-core@19.0.3
22.0.1
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
keycloak-core@20.0.5
22.0.1
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
keycloak-core@18.0.2
22.0.1
1
microcks/microcks:0.8.0e3a3e0c67b09
keycloak-core@3.4.0.Final
22.0.1
1
remche/shinyproxy:2.6.18bcda8a04d3b
keycloak-core@13.0.1
22.0.1
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
keycloak-core@19.0.1
22.0.1
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
keycloak-core@14.0.0
22.0.1
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
keycloak-core@20.0.1
22.0.1
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
keycloak-core@20.0.3
22.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.