Hacker News new | ask | show | jobs
by mmsc 208 days ago
Keycloak has various vulnerabilities they haven't even responded to after a month of reporting them.
2 comments

Disclose publicly then, if you haven't already?

Definitely makes things safer than users not knowing about them.

Are these documented anywhere? A full month with no response at all puts you firmly in “responsible disclosure” territory if they are not already publicly known. I'm pretty sure DayJob uses keycloak (or at least is assessing it - I'm a bit removed from that side of things these days) so that information could be pertinent to us.