# Keycloak 21.1.2 released

DevFeed: [Keycloak 21.1.2 released](<https://devfeed.tech/articles/keycloak-21-1-2-released-31612.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2023/06/keycloak-2112-released>)

Author: Keycloak Team

Published: 2023-06-28T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

## AI overview

Keycloak 21.1.2 was released on June 28, 2023. The release changes validation for non-HTTP(S) custom schemes in redirect URIs, requiring explicitly permitted redirect patterns, and includes enhancements and resolved issues across Keycloak components.

## Source excerpt

To download the release go to Keycloak downloads. Release notes Changes in validating schemes for valid redirect URIs If an application client is using non http(s) custom schemes, from now on the validation requires that a valid redirect pattern explicitly allows that scheme. Example patterns for allowing custom scheme are custom:/test, custom:/test/* or custom:*. For security reasons a general pattern like * does not cover them anymore. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #20613 Avoid using user property mapper when resolving root user attributes keycloak Bugs #17165 Issue with "User-Initiated Action Lifespan" keycloak admin/ui #19080 Vulnerable packages and or dependencies found in keycloak 21.0.1 quarkus distribution keycloak dist/quarkus #19286 CVE-2022-1471 keycloak dependencies #19491 Cannot set initial password for new users when using a custom UserFederation keycloak #19689 SAML Encryption: Missing Support for http://www.w3.org/2009/xmlenc11#rsa-oaep keycloak saml #19835 Keycloak issues on edge and after chrome upgarde to 112 (with experimental features) keycloak oidc #19865 Enabling Dynamic Scope missing in UI keycloak admin/ui #19879 Incorrect function is used in 'keycloak-admin-client' library in getToken function keycloak adapter/javascript #19883 Saving client admin-cli in master realm gives a javascript error keycloak admin/ui #19966 Paginating on the group tree view doesn't work keycloak admin/ui #19974 Dropdown options on Documentation pointing to 21.1 endpoint instead of latest and throwing 404 when clicking on it. keycloak docs #19981 Keycloak 21.1.1: Paging and filtering not working in "Assign roles" popup for Groups keycloak admin/ui #19999 Keycloak 21.1.1: filter on Sessions gets stuck keycloak admin/ui #20032 Processing of env variable references in config file broken keycloak dist/quarkus #20068 LDAP Mapper Action Menu Error keycloak admin/ui #20087 Event-Type