Red Hat Build of Keycloak
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*
- < 1.0
A vulnerability exists in Keycloak's SingleUseObjectProvider, which is a global key-value store that lacks proper type and namespace isolation. This flaw allows an attacker to delete arbitrary single-use entries, potentially enabling the replay of consumed action tokens, such as password reset links. Such exploitation could lead to unauthorized access or account compromise.
Exploitation of this vulnerability could allow for the unauthorized replay of action tokens, such as password reset links, leading to potential account compromise.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.