CVE-2020-14302

CVE-2020-14302

A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter. This flaw allows a malicious user to perform replay attacks.

Source: CVE-2020-14302

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다