5

CVE-2023-0264

User impersonation via stolen UUID code

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
Mögliche Gegenmaßnahme
Keycloak Server: Install latest version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatKeycloak Version < 18.0.6
RedhatSingle Sign-on Version < 7.6.2
   RedhatEnterprise Linux Version7.0
   RedhatEnterprise Linux Version8.0
   RedhatEnterprise Linux Version9.0
RedhatOpenshift Container Platform Version4.9
   RedhatEnterprise Linux Version8.0
RedhatOpenshift Container Platform Version4.10
   RedhatEnterprise Linux Version8.0
RedhatSingle Sign-on Version < 7.6.2
   RedhatEnterprise Linux Version8.0
RedhatSingle Sign-on Version- SwEditiontext-only
Weitere Schwachstelleninformationen
SystemKeycloak
Produkt Keycloak Server
Version < 21.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.94% 0.884
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 1.6 3.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.