VDB
Sign up
MEDIUM5.5

GHSA-68hw-vfh7-xvg8

Forced Logout in keycloak-connect

Quick fix

GHSA-68hw-vfh7-xvg8 — keycloak-connect: upgrade to the fixed version with the command below.

npm install keycloak-connect@4.8.3

Details

Versions of `keycloak-connect` prior to 4.4.0 are vulnerable to Forced Logout. The package fails to validate JWT signatures on the `/k_logout` route, allowing attackers to logout users and craft malicious JWTs with NBF values that prevent user access indefinitely.

## Recommendation

Upgrade to version 4.4.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/keycloak-connect
Introduced in: 0Fixed in: 4.8.3
Fixnpm install keycloak-connect@4.8.3

References