keycloak-auth-utils@3.0.0-cr.1 vulnerabilities

Keycloak OAuth client.

Direct Vulnerabilities

Known vulnerabilities in the keycloak-auth-utils package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Authentication Bypass

keycloak-auth-utils provides grant-management utilities for keycloak.

Affected versioms of this package are vulnerable to Authentication Bypass. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

How to fix Authentication Bypass?

Upgrade keycloak-auth-utils to version 3.0 or higher.

>=2.5.0 <3.1.0