VDB
Sign up
CRITICAL9.8

GHSA-mw35-24gh-f82w

keycloak-connect and keycloak-js improperly handle invalid tokens

Quick fix

GHSA-mw35-24gh-f82w — keycloak-connect: upgrade to the fixed version with the command below.

npm install keycloak-connect@3.1.0

Details

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/keycloak-connect
Introduced in: 2.5.0Fixed in: 3.1.0
Fixnpm install keycloak-connect@3.1.0
npm/keycloak-js
Introduced in: 2.5.0Fixed in: 3.1.0
Fixnpm install keycloak-js@3.1.0

References