A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter. This flaw allows a malicious user to perform replay attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2020-12-15T19:06:15

Updated: 2024-08-04T12:39:36.203Z

Reserved: 2020-06-17T00:00:00

Link: CVE-2020-14302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-15T20:15:15.573

Modified: 2020-12-18T16:19:25.617

Link: CVE-2020-14302

cve-icon Redhat

Severity : Low

Publid Date: 2020-11-26T00:00:00Z

Links: CVE-2020-14302 - Bugzilla