QID 981563
QID 981563: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-6pmv-7pr9-cgrj)
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6pmv-7pr9-cgrj for updates pertaining to this vulnerability.
Vendor References
- GHSA-6pmv-7pr9-cgrj -
github.com/advisories/GHSA-6pmv-7pr9-cgrj
CVEs related to QID 981563
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6pmv-7pr9-cgrj | org.keycloak:keycloak-core |
|