keycloak-connect@2.4.0-cr.1 vulnerabilities
Keycloak Connect Middleware
-
latest version
26.0.6
-
latest non vulnerable version
-
first published
10 years ago
-
latest version published
a day ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the keycloak-connect package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
keycloak-connect is a Identity and Access Management solution for modern Applications and Services. Affected versions of this package are vulnerable to Open Redirect.
via the Note: This package is deprecated and will be removed in the future. How to fix Open Redirect? Upgrade |
<21.0.1
|
keycloak-connect is an Identity and Access Management solution for modern Applications and Services. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). The Keycloak NodeJS adapter did not support How to fix Cross-site Scripting (XSS)? Upgrade |
<10.0.0
|
keycloak-connect is an Identity and Access Management solution for modern Applications and Services. Affected versions of this package are vulnerable to Denial of Service (DoS). The Node.js adapter did not properly verify the web token received from the server. An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely. How to fix Denial of Service (DoS)? Upgrade |
<4.4.0
|