cbcvebase.
CVE-2023-0264
published 2023-08-04

CVE-2023-0264: A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain…

medium5CVSS 3.1
AVNACHPRLUINSUCLILAL
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.

Affected

9 ranges
VendorProductVersion rangeFixed in
redhat.comkeycloak>= 18.0.6 < 18.0.618.0.6
redhatkeycloak< 18.0.618.0.6
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_ibm_z_systems
redhatopenshift_container_platform_ibm_z_systems
redhatsingle_sign-on< 7.6.27.6.2