QID 983165

QID 983165: Nodejs (npm) Security Update for keycloak-js (GHSA-mw35-24gh-f82w)

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-mw35-24gh-f82w for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 983165

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mw35-24gh-f82w keycloak-connect URL Logo github.com/advisories/GHSA-mw35-24gh-f82w
    GHSA-mw35-24gh-f82w keycloak-js URL Logo github.com/advisories/GHSA-mw35-24gh-f82w