Red Hat Bugzilla – Bug 1445271
CVE-2017-7474 keycloak-connect: auth token validity check ignored
Last modified: 2017-05-24 18:30:38 EDT
the nodejs auth-utils grant manager causes token validity to be ignored during validateGrant(). upstream jira KEYCLOAK-4771 pull request: https://github.com/keycloak/keycloak-nodejs-auth-utils/pull/49
Acknowledgments: Name: Nick Shearer (Quest)
This issue has been addressed in the following products: Via RHSA-2017:1203 https://access.redhat.com/errata/RHSA-2017:1203