NA

CVE-2023-0264

Published: 04/08/2023 Updated: 14/08/2023
CVSS v3 Base Score: 5 | Impact Score: 3.4 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat keycloak

redhat single_sign-on

redhat openshift_container_platform 4.9

redhat openshift_container_platform 4.10

redhat openshift_container_platform_for_ibm_linuxone 4.9

redhat openshift_container_platform_for_ibm_linuxone 4.10

redhat openshift_container_platform_ibm_z_systems 4.9

redhat openshift_container_platform_ibm_z_systems 4.10

redhat single sign-on -

Vendor Advisories

Synopsis Important: Red Hat Single Sign-On 762 for OpenShift image security and enhancement update Type/Severity Security Advisory: Important Topic A new image is available for Red Hat Single Sign-On 762, running on RedHat OpenShift Container Platform from the release of 311 up to the releaseof 4120Red Hat Product Security has rated t ...
概述 Important: Red Hat Single Sign-On 762 security update on RHEL 8 类型/严重性 Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems 标题 New Red Hat Single Sign-On 762 packages are now available for Red Hat Enterprise Linux 8Red H ...
Synopsis Important: Red Hat Single Sign-On 762 security update on RHEL 7 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 762 packages are now available for Red Hat Enterprise Linux 7Red Hat ...
Synopsis Important: Red Hat Single Sign-On 762 security update on RHEL 9 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 762 packages are now available for Red Hat Enterprise Linux 9Red Hat ...
Synopsis Important: Red Hat Single Sign-On 762 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 76 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2022-3143, CVE-2022-41881, CVE-2022-42003, CVE-2022-42004, CVE-2022-45787, CVE-2023-0264, CVE-2023-0482, CVE-2023-2454 Affected products and versions are listed below Please upgrade your version to the appropriate version ...

Github Repositories

A small PoC for the Keycloak vulnerability CVE-2023-0264

PoC for CVE-2023-0264 Keycloak vulnerability that allows session hijacking during authorization code flow See githubcom/advisories/GHSA-9g98-5mj6-f9mv Prerequisites Docker curl jq python3 or another tool to serve static files on HTTP Steps to reproduce Start Keycloak container with /run-keycloak-containersh Create two users alice and mallory with /create-userssh