CVE-2024-42163: Fiware Keyrock
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting the token for the password reset link.
Affected products
- Fiware Keyrock: up to and including 8.4
Published 2024-08-12. Last modified 2026-06-17.