PT-2026-47027 · Unknown+1 · Uds-Identity-Config+1
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UDS Identity Config versions 0.11.0 through 0.26.0
Description
A logic error exists in the
client-kubernetes-secret Keycloak client authenticator. This error causes the submitted client secret to be overwritten with the mounted Kubernetes secret before the comparison occurs. An attacker who can access the Keycloak token endpoint and knows a client id using this authenticator can authenticate as that client using any value for the client secret to obtain OAuth2 tokens scoped to the client's service account. If the uds-operator client is targeted, the obtained token can be used to register or modify other clients.Recommendations
Update to version 0.26.1.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak
Uds-Identity-Config