MEDIUM 5.4 Maven
Incorrect Authorization in keycloak
GHSA-p225-pc2x-4jpm · CVE-2020-1725
Published · Modified
Description
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
Ready to move
Start Securing
Free, no credit card | First findings in minutes