VDB
Sign up
MEDIUM5.3

GHSA-rx66-hj7g-28h7

Keycloak: Replay of action tokens via improper handling of single-use entries

Quick fix

GHSA-rx66-hj7g-28h7 — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-services

Details

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to unauthorized access or account compromise.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 26.5.7
Fix# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-services

References