Описание
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
A flaw was found in Keycloak's OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, Integrity, and availability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat A-MQ Online | keycloak-services | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-services | Not affected | ||
| Red Hat Single Sign-On 7 | Fixed | RHSA-2023:1049 | 01.03.2023 | |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak | Fixed | RHSA-2023:1043 | 01.03.2023 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak | Fixed | RHSA-2023:1044 | 01.03.2023 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak | Fixed | RHSA-2023:1045 | 01.03.2023 |
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8 | Fixed | RHSA-2023:1047 | 01.03.2023 |
Показывать по
Дополнительная информация
Статус:
4.6 Medium
CVSS3
Связанные уязвимости
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
A flaw was found in Keycloaks OpenID Connect user authentication, whic ...
Keycloak vulnerable to user impersonation via stolen UUID code
Уязвимость службы OpenID Connect Login программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю создать новые токены сеанса и оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
4.6 Medium
CVSS3