Description
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1790759
Related Vulnerabilities
CVE-2021-25329 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2019-1003082 Vulnerability in maven package org.jenkins-ci.plugins:gearman-plugin
CVE-2017-2606 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2015-5237 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2019-1003077 Vulnerability in maven package org.jenkins-ci.plugins:audit2db