PT-2020-14897 · Red Hat · Keycloak
Paramvir Jindal
·
Published
2020-09-16
·
Updated
2022-02-09
·
CVE-2020-1694
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak versions prior to 10.0.0
Description
A flaw was found in Keycloak where the NodeJS adapter did not support the verify-token-audience. This results in some users having access to sensitive information outside of their permissions.
Recommendations
For versions prior to 10.0.0, update to version 10.0.0 or later to resolve the issue.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak