Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.9 Maven

Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak

GHSA-72j4-94rx-cr6w · CVE-2020-1694

Published · Modified

Description

A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.

Ready to move

Start Securing

Free, no credit card | First findings in minutes