keycloak-services is vulnerable to Authentication Bypass
91
Critical Risk
keycloak-services tracks reset-credentials flow progress with an AUTHENTICATION_SELECTOR_SCREEN_DISPLAYED auth note and lets the reset-email authenticator succeed without a matching email action token. An unauthenticated caller who knows a username can make a request to the reset-credentials endpoint and skip email verification, landing on the password-update step. Before the fix this lets the caller set a new password for any user. The fix binds the selector note to the current execution ID and rejects reset email actions that lack a matching token.
You are affected if you are using a version that falls within the vulnerable range and the Forgot password feature is enabled.
keycloak-services is vulnerable to Authentication Bypass in versions 26.0.0 - 26.7.1.
Upgrade the org.keycloak:keycloak-services library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant