Fedora Account System
Red Hat Associate
Red Hat Customer
A vulnerability was found in keycloak, where it is common for password reset functionality to include the Host header value when creating password reset links that use a generated secret token. If the application processes an attacker-controlled domain to create a password reset link, the victim may click on the link in the email and allow the attacker to obtain the reset token, thus resetting the victim’s password. References: https://issues.redhat.com/browse/KEYCLOAK-14656
Red Hat Product Security does not consider this to be a vulnerability. As it is recommended to use Keycloak with a hostname, or a reverse proxy should be placed in front of Keycloak that validates the Host header
Statement: Red Hat Product Security does not consider this to be a vulnerability. As it is recommended to use Keycloak with a hostname, or a reverse proxy should be placed in front of Keycloak that validates the Host header. https://www.keycloak.org/docs/latest/server_installation/#_hostname