A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-287"
],
"nvd_published_at": "2020-05-12T21:15:00Z",
"github_reviewed_at": "2021-04-01T22:16:07Z",
"github_reviewed": true
}