cbcvebase.
CVE-2023-2585
published 2023-12-21

CVE-2023-2585: Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof…

high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.

Affected

9 ranges
VendorProductVersion rangeFixed in
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_z
redhatopenshift_container_platform_for_ibm_z
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatsingle_sign-on