Keycloak 26.7.3

26.7.3
Security 20
  • Fix LDAP client implementation certificate hostname verification
  • Fix required signed-JWT assertion policy bypass with unsigned assertion headers
  • Fix organization managers creating managed members through stored registration links without manage-users permission
  • Fix realm default-group reads disclosing hidden groups under FGAP v2
  • Fix missing per-role authorization on RoleContainerResource composite endpoints
  • Fix authorization codes being retargeted to another client session

From Keycloak

View original

Upgraded? How did it go?

Discussion