Severe security issue in Keycloak >= 12.0.0 and <= 15.1.0

I strongly recommend to update your Keycloak deployments to latest 15.1.1 or 16.0.0!

https://groups.google.com/g/keycloak-user/c/GbegUKYgeLg/m/5O77Tg9mCQAJ

4 Likes

So Keycloak 10 is not vulnerable?

Don‘t know. :man_shrugging:
But KC10 is already 1,5 yrs old (at least) and thus has other issues. So, you always should upgrade to the most recent version.

More info: