PT-2024-11925 · Red Hat · Keycloak

·

CVE-2023-0657

·

Published

2024-04-17

·

Updated

2024-11-18

CVSS v3.1

3.4

Low

VectorAV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw was found in Keycloak due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass by Spoofing

Improper Access Control

Improper Verification of Cryptographic Signature

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-0657
GHSA-7FPJ-9HR8-28VH

Affected Products

Keycloak