OIDC Logout redirect in keycloak
Package
Affected versions
< 18.0.0
Patched versions
18.0.0
Description
Published by the National Vulnerability Database
Feb 11, 2021
Published to the GitHub Advisory Database
Apr 28, 2022
Reviewed
Apr 28, 2022
Last updated
Jan 30, 2023
A flaw was found in keycloak. The OIDC logout endpoint does not have CSRF protection. The highest threat from this vulnerability is to system availability.
References