Description
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1941565
Related Vulnerabilities
CVE-2023-29511 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2023-22457 Vulnerability in maven package org.xwiki.contrib:application-ckeditor-ui
CVE-2021-3424 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-14967 Vulnerability in npm package jsrsasign
CVE-2023-31579 Vulnerability in maven package top.tangyh.basic:lamp-core