Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 Maven

Keycloak Insufficient Session Expiry

GHSA-8xj2-47xw-q78c · CVE-2020-1724

Published · Modified

Description

A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.

Ready to move

Start Securing

Free, no credit card | First findings in minutes