Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Source: The Hacker News

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.

The vulnerability, assigned the CVE iden


Read original