LOW 3.8 Maven
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
GHSA-gc52-xj6p-9pxp · CVE-2019-3868
Published · Modified
Description
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user?s browser session.
Ready to move
Start Securing
Free, no credit card | First findings in minutes