REDHAT-BUG-1978196: Medium severity keycloak vulnerability
Anyone can register a new device when there is no device registered for passwordless login for any user.
https://issues.redhat.com/browse/KEYCLOAK-18500
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1978196?
The severity of REDHAT-BUG-1978196 is considered critical due to the potential for unauthorized device registration.
How do I fix REDHAT-BUG-1978196?
To fix REDHAT-BUG-1978196, ensure devices are properly registered for passwordless login and apply the latest security patches related to the vulnerability.
What systems are affected by REDHAT-BUG-1978196?
REDHAT-BUG-1978196 affects users of Red Hat Keycloak when no device is registered for passwordless login.
Can REDHAT-BUG-1978196 lead to security breaches?
Yes, REDHAT-BUG-1978196 can lead to security breaches by allowing unauthorized users to register new devices.
Is there a workaround for REDHAT-BUG-1978196?
A temporary workaround for REDHAT-BUG-1978196 includes enforcing manual device registration to prevent unauthorized access.