8.1
CVE-2023-2585
- EPSS 0.69%
- Veröffentlicht 21.12.2023 10:15:34
- Zuletzt bearbeitet 21.11.2024 07:58:52
- Erkennungen
Keycloak: client access via device auth request spoof
Client Spoofing within the Keycloak Device Authorisation Grant
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.
Mögliche Gegenmaßnahme
Keycloak Server: Install latest version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Single Sign-on Version 7.6
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Openshift Container Platform Version 4.11
Redhat ≫ Openshift Container Platform Version 4.12
Redhat ≫ Openshift Container Platform For Ibm Z Version 4.9
Redhat ≫ Openshift Container Platform For Ibm Z Version 4.10
Redhat ≫ Openshift Container Platform For Linuxone Version 4.9
Redhat ≫ Openshift Container Platform For Linuxone Version 4.10
Redhat ≫ Openshift Container Platform For Power Version 4.9
Redhat ≫ Openshift Container Platform For Power Version 4.10
Redhat ≫ Single Sign-on Version - SwEdition text-only
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemKeycloak
≫
Produkt
Keycloak Server
Version
< 21.1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.69% | 0.483 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
|
| RedHat | 3.5 | 0.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
|
CWE-358 Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
https://access.redhat.com/errata/RHSA-2023:3883
https://access.redhat.com/errata/RHSA-2023:3884
https://access.redhat.com/errata/RHSA-2023:3885
https://access.redhat.com/errata/RHSA-2023:3888
https://access.redhat.com/errata/RHSA-2023:3892
https://access.redhat.com/security/cve/CVE-2023-2585
https://bugzilla.redhat.com/show_bug.cgi?id=2196335
https://github.com/keycloak/keycloak/security/advisories/GHSA-f5h4-wmp5-xhg6