Find published dossiers by topic, company, product or technology.

Showing 201–220 of 240 dossiers

Keycloak patches a critical password-reset flaw that can let unauthenticated attackers take over any account

This is an identity-system failure rather than an application bug: a vulnerable Keycloak deployment can let an attacker turn the legitimate “forgot password” flow into full account takeover without credentials or victim interaction. Upgrade is the proper fix; disabling Forgot Password in every realm is Red Hat’s temporary mitigation.