keycloak-21.1
Chainguard
Status
Impact
This vulnerability affects keycloak-services 21.1.2, which is a self-contained component built from the same source repository as the package. The vulnerability is inherent to Keycloak version 21.1.2 and cannot be fixed through dependency updates. Keycloak 21.1.2 reached its end-of-life on July 11, 2023. GitHub Advisory API indicates no patched version is available (firstPatchedVersion: null). Customers should migrate to supported Keycloak versions (26.x series) to address this and other security vulnerabilities.
Status