Description
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
Remediation
References
https://issues.redhat.com/browse/KEYCLOAK-16550
https://bugzilla.redhat.com/show_bug.cgi?id=1765129
Related Vulnerabilities
CVE-2022-36913 Vulnerability in maven package org.jenkins-ci.plugins:openstack-heat
CVE-2022-28731 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2022-23302 Vulnerability in maven package log4j:log4j
CVE-2019-7619 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2021-41184 Vulnerability in maven package org.webjars.npm:jquery-ui