CVE Database
/

CVE-2020-1694

Back to search

CVE-2020-1694

Published: Sep 16, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.

VendorProductVersions

n/a

keycloak

affected
all versions before 10.0.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now