CVE-2020-1725: Red Hat Keycloak
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
Affected products
- Red Hat Keycloak: before 13.0.0 (fixed in 13.0.0)
Published 2021-01-28. Last modified 2026-06-17.