Description
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1941565
Related Vulnerabilities
CVE-2022-29770 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2016-8629 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-26870 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify
CVE-2018-14642 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-35153 Vulnerability in maven package org.xwiki.platform:xwiki-platform-appwithinminutes-ui