Improper authorization control for web services In org.keycloak:keycloak-core
Description
Improper Authentication in org.keycloak:keycloak-core It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 2.3.0 |
Aliases
1. 2. 3. 4. 5.