VYPR

Keycloak Nodejs Auth Utils

Sign in to watch

by Keycloak

CVEs (1)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-7474Cri0.649.80.02May 12, 2017It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.