Description
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1790759
Related Vulnerabilities
CVE-2020-11975 Vulnerability in maven package org.apache.unomi:unomi-common
CVE-2022-40634 Vulnerability in maven package org.craftercms:craftercms
CVE-2023-30526 Vulnerability in maven package org.jenkins-ci.plugins:reportportal
CVE-2023-30518 Vulnerability in maven package io.jenkins.plugins:thycotic-secret-server