It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
{
"cwe_ids": [
"CWE-287",
"CWE-384"
],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:27:42Z",
"nvd_published_at": null,
"severity": "HIGH"
}