← Back to CVE List

CVE-2020-1694

Published: 2020-09-16T19:15Z
Last Modified: 2024-11-21T05:11Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt