← back
CVE-2020-1694CWE-183

CVE-2020-1694

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.6%
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
nono source reports it
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
Affected products
n/a · keycloak