5

CVE-2023-0264

User impersonation via stolen UUID code

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
Mögliche Gegenmaßnahme
Keycloak Server: Install latest version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Keycloak Version < 18.0.6
Redhat ≫ Single Sign-on Version < 7.6.2
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
   Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Openshift Container Platform Version 4.9
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.10
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Single Sign-on Version < 7.6.2
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Single Sign-on Version - SwEdition text-only
Weitere Schwachstelleninformationen
SystemKeycloak
≫
Produkt Keycloak Server
Version < 21.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.27% 0.661
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 1.6 3.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://access.redhat.com/security/cve/CVE-2023-0264
Vendor Advisory
https://github.com/keycloak/keycloak/security/advisories/GHSA-9g98-5mj6-f9mv
Third Party Advisory