Predictable password in Keycloak
Critical severity
GitHub Reviewed
Published
Apr 15, 2020
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 2, 2020
Reviewed
Apr 15, 2020
Published to the GitHub Advisory Database
Apr 15, 2020
Last updated
Feb 1, 2023
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.
References