Description
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1790759
Related Vulnerabilities
CVE-2020-15092 Vulnerability in npm package @knight-lab/timelinejs
CVE-2016-10735 Vulnerability in npm package bootstrap-sass
CVE-2020-2209 Vulnerability in maven package org.jenkins-ci.plugins:testcomplete
CVE-2023-24998 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2020-25802 Vulnerability in maven package org.craftercms:crafter-studio