CVE-2023-0264
published 2023-08-04CVE-2023-0264: A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain…
PriorityP431medium5CVSS 3.1
AVNACHPRLUINSUCLILAL
EPSS
1.27%
66.7th percentile
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat.com | keycloak | >= 18.0.6 < 18.0.6 | 18.0.6 |
| redhat | keycloak | < 18.0.6 | 18.0.6 |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_ibm_linuxone | — | — |
| redhat | openshift_container_platform_for_ibm_linuxone | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | single_sign-on | < 7.6.2 | 7.6.2 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: user impersonation via stolen uuid code
vendor_redhat·2023-02-28·CVSS 5.0
CVE-2023-0264 [MEDIUM] CWE-303 keycloak: user impersonation via stolen uuid code
keycloak: user impersonation via stolen uuid code
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
A flaw was found in Keycloak's OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, Integrity, and availability.
Package: keycloak-services (Red
GHSA
Keycloak vulnerable to user impersonation via stolen UUID code
ghsa·2023-03-02
CVE-2023-0264 [HIGH] CWE-287 Keycloak vulnerable to user impersonation via stolen UUID code
Keycloak vulnerable to user impersonation via stolen UUID code
Keycloak's OpenID Connect user authentication was found to incorrectly authenticate requests. An authenticated attacker who could also obtain a certain piece of info from a user request, from a victim within the same realm, could use that data to impersonate the victim and generate new session tokens.
OSV
Keycloak vulnerable to user impersonation via stolen UUID code
osv·2023-03-02
CVE-2023-0264 [HIGH] Keycloak vulnerable to user impersonation via stolen UUID code
Keycloak vulnerable to user impersonation via stolen UUID code
Keycloak's OpenID Connect user authentication was found to incorrectly authenticate requests. An authenticated attacker who could also obtain a certain piece of info from a user request, from a victim within the same realm, could use that data to impersonate the victim and generate new session tokens.
No detection rules found.
No public exploits indexed.
2023-08-04
Published