Authentication mechanism absence or evasion In keycloak-connect
Description
Forced Logout in keycloak-connect
Versions of keycloak-connect prior to 4.4.0 are vulnerable to Forced Logout. The package fails to validate JWT signatures on the /k_logout route, allowing attackers to logout users and craft malicious JWTs with NBF values that prevent user access indefinitely.
Recommendation
Upgrade to version 4.4.0 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 4.8.3 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.