Keycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in keycloak (CVE-2025-0604) | HOL Guard CVE