VDB
Sign up
LOW3.4

GHSA-7fpj-9hr8-28vh

Keycloak vulnerable to impersonation via logout token exchange

Quick fix

GHSA-7fpj-9hr8-28vh — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>22.0.10</version> for org.keycloak:keycloak-services

Details

Keycloak was found to not properly enforce token types when validating signatures locally. An authenticated attacker could use this flaw to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 22.0.10
Fix# pom.xml: bump <version>22.0.10</version> for org.keycloak:keycloak-services
Maven/org.keycloak:keycloak-services
Introduced in: 23.0.0Fixed in: 24.0.3
Fix# pom.xml: bump <version>24.0.3</version> for org.keycloak:keycloak-services

References