CVE-2020-1694 PUBLISHED CVSS 4 MEDIUM

A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.

EPSS 0.27% · 50.8th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
0.27%
50.8th percentile

Affected Products

VendorProductVersions
Mavenorg.keycloak:keycloak-parent0
redhatkeycloak0
n/akeycloakall versions before 10.0.0

Timeline

References

Open in Interactive Console →