Low severity3.3NVD Advisory· Published Feb 11, 2021· Updated Jun 17, 2026
CVE-2020-10734
CVE-2020-10734
Description
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-oidc-client-adapter-pomMaven | < 18.0.0 | 18.0.0 |
Affected products
6- cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-rvjg-gxwx-j5gfghsaADVISORY
- issues.redhat.com/browse/KEYCLOAK-13653nvdPermissions RequiredVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-10734ghsaADVISORY
- github.com/keycloak/keycloak/security/advisories/GHSA-rvjg-gxwx-j5gfghsaWEB
News mentions
0No linked articles in our index yet.