LOW 3.8 Maven
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
GHSA-gc52-xj6p-9pxp · CVE-2019-3868
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user?s browser session.
Ready to move
Start Securing
Free, no credit card | First findings in minutes