cbcvebase.
CVE-2021-3461
published 2022-04-01

CVE-2021-3461: A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type…

high7.1CVSS 3.1
AVLACLPRNUIRSUCHIHAN
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

Affected

5 ranges
VendorProductVersion rangeFixed in
redhatkeycloak
redhatkeycloak
redhatsingle_sign-on
redhatsingle_sign-on
redhatsingle_sign-on