CVE-2020-1694

Publication date

2020-09-16 18:03:14

Family

redhat

State

PUBLISHED

Description

A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.