OSV 1.4.0 · github-reviewed · 修改于 2021-04-02 05:11
发布时间
2022-02-09 08:57
GitHub 审查时间
2021-04-02 05:11
NVD 发布时间
2020-09-17 03:15
源文件
advisories/github-reviewed/2022/02/GHSA-72j4-94rx-cr6w/GHSA-72j4-94rx-cr6w.json
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.