26.7.3
9 years ago
4 days ago
Known vulnerabilities in the org.keycloak:keycloak-server-spi-private package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Reliance on Untrusted Inputs in a Security Decision through the client authentication flow in the client policies and assertion handling components. An attacker can authenticate with weaker client credentials by supplying a fake unsigned assertion header that makes the server believe the policy requirements have been satisfied. This defeats administrator-mandated requirements for signed JWT assertions and lets a client complete authentication with a simpler method such as a client secret, weakening client authentication controls. How to fix Reliance on Untrusted Inputs in a Security Decision? Upgrade | [13.0.0,26.7.3) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Missing Authorization through the user creation path in How to fix Missing Authorization? Upgrade | [0,26.7.3) |
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services. Affected versions of this package are vulnerable to Information Exposure through the Notes
How to fix Information Exposure? Upgrade | [0,26.7.3) |