CVE-2024-42164: Fiware Keyrock

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.

Affected products

  • Fiware Keyrock: up to and including 8.4

Published 2024-08-12. Last modified 2026-06-17.