Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0091

Опубликовано: 13 янв. 2023
Источник: nvd
CVSS3: 3.8
EPSS Низкий

Описание

A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00466
Низкий

3.8 Low

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 3.8
redhat
почти 4 года назад

A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

CVSS3: 3.8
debian
больше 3 лет назад

A flaw was found in Keycloak, where it did not properly check client t ...

CVSS3: 6.5
github
больше 3 лет назад

Keycloak has lack of validation of access token on client registrations endpoint

EPSS

Процентиль: 39%
0.00466
Низкий

3.8 Low

CVSS3

Дефекты

CWE-863
CWE-863