Launch Week Day 1: Announcing Security Design Review
LOW 3.8 Maven

Exposure of Sensitive Information to an Unauthorized Actor in Keycloak

GHSA-gc52-xj6p-9pxp · CVE-2019-3868

Published · Modified

Description

Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user?s browser session.

Ready to move

Start Securing

Free, no credit card | First findings in minutes