Vulnerabilities (CVE)

Filtered by vendor Keycloak Subscribe
Filtered by product Keycloak-nodejs-auth-utils
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-7474 1 Keycloak 1 Keycloak-nodejs-auth-utils 2024-02-04 7.5 HIGH 9.8 CRITICAL
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.