High severity authorization #vulnerability in Keycloak:

  1. Of course it’s because of JWT
  2. If a project with a sole purpose is authn/authz is getting #JWT wrong, you probably are too.

https://github.com/advisories/GHSA-hcvw-475w-8g7p