Description
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1718
Related Vulnerabilities
CVE-2020-17530 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-31522 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2021-26118 Vulnerability in maven package org.apache.activemq:artemis-openwire-protocol
CVE-2019-19703 Vulnerability in maven package io.ktor:ktor-client-core
CVE-2022-35912 Vulnerability in maven package org.grails:grails-databinding