#VU21706 Insufficiently protected credentials in Keycloak - CVE-2019-3868
Published: October 10, 2019
Keycloak
Keycloak
Description
The vulnerability allows a remote attacker to hijack user's session.
The vulnerability exists due to software may use the end user token (access or id token JWT) as a session cookie for browser sessions for OIDC. A remote attacker that has access to the service provider backend can hijack the user's browser session and gain unauthorized access to the application.