QID 983152
QID 983152: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-959q-32g8-vvp7)
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-959q-32g8-vvp7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-959q-32g8-vvp7 -
github.com/advisories/GHSA-959q-32g8-vvp7
CVEs related to QID 983152
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-959q-32g8-vvp7 | org.keycloak:keycloak-core |
|