CVE-2020-10734: CSRF
A vulnerability was found in keycloak in the way that the OIDC logout endpoint do not have CSRF protection.
Reference: https://issues.redhat.com/browse/KEYCLOAK-13653
Other sources
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10734?
CVE-2020-10734 is a vulnerability found in Keycloak that affects versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes.
What is the severity of CVE-2020-10734?
The severity of CVE-2020-10734 is low, with a severity value of 3.3.
How does CVE-2020-10734 impact Keycloak?
CVE-2020-10734 impacts Keycloak by not having CSRF protection in the OIDC logout endpoint.
Which software is affected by CVE-2020-10734?
CVE-2020-10734 affects Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes.
How can I mitigate CVE-2020-10734?
To mitigate CVE-2020-10734, update to version 18.0.0 or later of Keycloak.