Vulnerability Description
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.
Affected Platforms (CPE)
📦
Keycloak Nodejs Auth Utils
= 2.5.0📦
Keycloak Nodejs Auth Utils
= 2.5.0📦
Keycloak Nodejs Auth Utils
= 2.5.1📦
Keycloak Nodejs Auth Utils
= 2.5.2📦
Keycloak Nodejs Auth Utils
= 2.5.3📦
Keycloak Nodejs Auth Utils
= 2.5.4📦
Keycloak Nodejs Auth Utils
= 2.5.5📦
Keycloak Nodejs Auth Utils
= 2.5.6📦
Keycloak Nodejs Auth Utils
= 2.5.7📦
Keycloak Nodejs Auth Utils
= 3.0.0📦
Keycloak Nodejs Auth Utils
= 3.0.0