Launch Week Day 1: Announcing Security Design Review
HIGH 7.1 Maven

Keycloak insufficient session expiration

GHSA-cm29-6wx7-p874 · CVE-2021-3461

Published · Modified

Description

A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

Ready to move

Start Securing

Free, no credit card | First findings in minutes