GHSA-rvjg-gxwx-j5gf
GitHub Security Advisory
OIDC Logout redirect in keycloak
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
A flaw was found in keycloak. The OIDC logout endpoint does not have CSRF protection. The highest threat from this vulnerability is to system availability.
Affected Packages
Maven
org.keycloak:keycloak-oidc-client-adapter-pom
Affected versions:
0
(fixed in 18.0.0)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: September 22, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.