Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing…
redhat·CWE-358·Published 2023-06-30