macOS • xterm-256color • zsh 663 views

CVE-2020-27838 refers to a flaw discovered in the client registration endpoint of Keycloak, an open-source identity and access management (IAM) solution. This endpoint allows developers to register new client applications within a Keycloak server. The vulnerability arises because, in Keycloak versions before 13.0.0, the client registration endpoint lacked proper authentication for fetching information about public clients.

To know more about this bug, read our blog

https://blogs.cappriciosec.com/cve/151/CVE-2020-27838%20-%20When%20Public%20Client%20Secrets%20Aren’t%20So%20Public

More recordings by cappriciosec

CVE-2023-27524 0:19

by cappriciosec