QID 983165
QID 983165: Nodejs (npm) Security Update for keycloak-js (GHSA-mw35-24gh-f82w)
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mw35-24gh-f82w for updates pertaining to this vulnerability.
Vendor References
- GHSA-mw35-24gh-f82w -
github.com/advisories/GHSA-mw35-24gh-f82w
CVEs related to QID 983165
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mw35-24gh-f82w | keycloak-connect |
|
|
| GHSA-mw35-24gh-f82w | keycloak-js |
|