A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
{
"cwe_ids": [
"CWE-613"
],
"github_reviewed": true,
"severity": "HIGH",
"github_reviewed_at": "2023-07-11T23:38:35Z",
"nvd_published_at": "2022-04-01T23:15:00Z"
}