keycloak-angular is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
18
Low Risk
Affected versions of this package are vulnerable due to a flawed implementation of the customBearerTokenInterceptor, which may cause bearer tokens to be unintentionally sent to third-party services. This results in inadvertent token exposure, potentially allowing unauthorized access by recipients that should not have access to the token.
You are affected if you are using a version that falls within the vulnerable range and you are using the customBearerTokenInterceptor implementation.
keycloak-angular is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 19.0.0 - 19.0.2.
Upgrade the keycloak-angular library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant