MEDIUM 4.9 Maven
Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak
GHSA-72j4-94rx-cr6w · CVE-2020-1694
Published · Modified
Description
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes