Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-0657

Опубликовано: 16 апр. 2024
Источник: redhat
CVSS3: 3.4
EPSS Низкий

Описание

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7rh-sso7-keycloakFix deferred
Red Hat build of Keycloak 22rhbk/keycloak-operator-bundleFixedRHSA-2024:186716.04.2024
Red Hat build of Keycloak 22rhbk/keycloak-rhel9FixedRHSA-2024:186716.04.2024
Red Hat build of Keycloak 22rhbk/keycloak-rhel9-operatorFixedRHSA-2024:186716.04.2024
Red Hat build of Keycloak 22.0.10keycloakFixedRHSA-2024:186816.04.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-273
https://bugzilla.redhat.com/show_bug.cgi?id=2166728keycloak: impersonation via logout token exchange

EPSS

Процентиль: 12%
0.0004
Низкий

3.4 Low

CVSS3

Связанные уязвимости

CVSS3: 3.4
nvd
около 1 года назад

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

CVSS3: 3.4
debian
около 1 года назад

A flaw was found in Keycloak. This issue occurs due to improperly enfo ...

CVSS3: 3.4
github
почти 2 года назад

Keycloak vulnerable to impersonation via logout token exchange

EPSS

Процентиль: 12%
0.0004
Низкий

3.4 Low

CVSS3