REDHAT-BUG-2448351: Medium severity Red Hat Keycloak vulnerability
Keycloak's SingleUseObjectProvider is a global flat key-value store used without type or namespace isolation. This allows an attacker to delete arbitrary single-use entries, enabling the replay of consumed action tokens such as password reset links. Requirements to exploit:
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2448351?
The severity of REDHAT-BUG-2448351 is high due to the potential for arbitrary deletion of critical single-use entries.
How do I fix REDHAT-BUG-2448351?
To fix REDHAT-BUG-2448351, you should update to the latest patched version of Red Hat Keycloak issued by Red Hat.
What can an attacker do with REDHAT-BUG-2448351?
An attacker can exploit REDHAT-BUG-2448351 to delete single-use entries, allowing the replay of action tokens like password reset links.
Which versions of Red Hat Keycloak are affected by REDHAT-BUG-2448351?
All versions of Red Hat Keycloak that utilize the vulnerable SingleUseObjectProvider are affected by REDHAT-BUG-2448351.
What is the impact of exploiting REDHAT-BUG-2448351?
Exploiting REDHAT-BUG-2448351 could lead to unauthorized access to user accounts through replayed password reset links.