Description
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1718
Related Vulnerabilities
CVE-2016-3088 Vulnerability in maven package org.apache.activemq:activemq-fileserver
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-legacy-oldcore
CVE-2020-8203 Vulnerability in maven package org.webjars:lodash
CVE-2022-34184 Vulnerability in maven package org.jenkins-ci.plugins:crx-content-package-deployer
CVE-2022-21803 Vulnerability in maven package org.webjars.npm:nconf