Status
Justification
Impact
This vulnerability was discovered and fixed in Keycloak in 2017, specifically in commit 463661b051efa28e85e9da16a206bad6b1b1bb63 and released in version 3.4.0. Our Keycloak packaging began more than 6 years after this vulnerability was patched. The vulnerable code has been entirely rewritten in newer versions. This is a false positive triggered by security scanners matching on the package name without considering the version timeline.
Status