Insecure session management In org.keycloak:keycloak-services
Description
Keycloak Insufficient Session Expiry A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 9.0.2 | ||
maven | 9.0.2 | ||
npm | 9.0.2 |
Aliases
1. 2. 3. 4. 5.
References
1.