CVE-2020-1725: Red Hat Keycloak

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.

Affected products

  • Red Hat Keycloak: before 13.0.0 (fixed in 13.0.0)

Published 2021-01-28. Last modified 2026-06-17.