Back to bug 1831662

Who When What Removed Added
Guilherme de Almeida Suckevicz 2020-05-05 12:54:12 UTC CC security-response-team
Guilherme de Almeida Suckevicz 2020-05-05 12:56:11 UTC Blocks 1823476
Joshua Padman 2020-05-06 05:27:29 UTC CC dbecker, jjoyce, jschluet, kbasil, lhh, lpeer, mburns, sclewis, slinaber
Marian Rehak 2020-05-06 10:55:00 UTC Summary EMBARGOED keycloak: OIDC logout endpoint CSRF EMBARGOED CVE-2020-10734 keycloak: OIDC logout endpoint CSRF
Alias CVE-2020-10734
Paramvir jindal 2021-02-10 06:21:04 UTC Group security, qe_staff
Summary EMBARGOED CVE-2020-10734 keycloak: OIDC logout endpoint CSRF CVE-2020-10734 keycloak: OIDC logout endpoint CSRF
Eric Christensen 2021-02-16 20:41:25 UTC Doc Text A flaw was found in keycloak. The OIDC logout endpoint does not have CSRF protection. The highest threat from this vulnerability is to system availability.
Paramvir jindal 2022-02-15 16:02:54 UTC Blocks 2026780
CC psampaio
Red Hat Bugzilla 2022-04-19 04:38:57 UTC CC ggaughan
Red Hat Bugzilla 2022-08-31 22:23:08 UTC Fixed In Version keycloak 18.0.0
CC mszynkie
Red Hat Bugzilla 2022-10-28 13:13:01 UTC CC krathod
Red Hat Bugzilla 2022-12-31 23:43:17 UTC CC aboyko
Red Hat Bugzilla 2023-05-15 18:09:22 UTC CC drieden
Red Hat Bugzilla 2023-07-07 08:35:45 UTC CC security-response-team
Assignee security-response-team nobody

Back to bug 1831662