It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain…
redhat·CWE-613·Published 2017-10-26