Description
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1941565
Related Vulnerabilities
CVE-2022-24375 Vulnerability in npm package node-opcua
CVE-2020-14359 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2017-12617 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2020-36048 Vulnerability in maven package org.webjars.bower:engine.io
CVE-2023-46243 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore