Keycloak was found to not properly enforce token types when validating signatures locally. An authenticated attacker could use this flaw to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.
{
"severity": "LOW",
"github_reviewed": true,
"cwe_ids": [
"CWE-273",
"CWE-284",
"CWE-287",
"CWE-290",
"CWE-347"
],
"nvd_published_at": "2024-11-17T11:15:05Z",
"github_reviewed_at": "2024-04-17T18:25:59Z"
}