Description
Keycloak is an open source identity and access management solution.
Acunetix determined that it was possible to access a 'client secret' without authentication.
Remediation
Upgrade to the latest version of KeyCloak
References
Related Vulnerabilities
Envoy Proxy Missing Authentication for Critical Function Vulnerability (CVE-2022-29226)
WebLogic CVE-2018-2625 Vulnerability (CVE-2018-2625)
OpenSSL Cryptographic Issues Vulnerability (CVE-2009-3555)
MySQL CVE-2012-0489 Vulnerability (CVE-2012-0489)
Joomla Improper Input Validation Vulnerability (CVE-2016-8870)