cbcvebase.
CVE-2023-0264
published 2023-08-04

CVE-2023-0264: A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain…

PriorityP431medium5CVSS 3.1
AVNACHPRLUINSUCLILAL
EPSS
1.27%
66.7th percentile
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.

Affected

9 ranges
VendorProductVersion rangeFixed in
redhat.comkeycloak>= 18.0.6 < 18.0.618.0.6
redhatkeycloak< 18.0.618.0.6
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_ibm_z_systems
redhatopenshift_container_platform_ibm_z_systems
redhatsingle_sign-on< 7.6.27.6.2

CVSS provenance

nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.