Improper authorization control for web services In org.keycloak:keycloak-services
Description
Keycloak vulnerable to impersonation via logout token exchange Keycloak was found to not properly enforce token types when validating signatures locally. An authenticated attacker could use this flaw to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 22.0.10, 24.0.3 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2.