Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released patches to address a critical security flaw in the opensource identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset The vulnerability assigned the CVE identifier CVE202618963 is rated 91 on the CVSS scoring system by Red Hat which acts as