8.1
CVSSv3

CVE-2023-2585

Published: 21/12/2023 Updated: 02/01/2024
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat single_sign-on 7.6

redhat openshift_container_platform 4.11

redhat openshift_container_platform 4.12

redhat openshift_container_platform_for_ibm_z 4.9

redhat openshift_container_platform_for_ibm_z 4.10

redhat openshift_container_platform_for_linuxone 4.9

redhat openshift_container_platform_for_linuxone 4.10

redhat openshift_container_platform_for_power 4.9

redhat openshift_container_platform_for_power 4.10

redhat single sign-on -

Vendor Advisories

Synopsis Important: Red Hat Single Sign-On 764 for OpenShift image security enhancement update Type/Severity Security Advisory: Important Topic A new image is available for Red Hat Single Sign-On 764, running on OpenShift Container Platform 310 and 311, and 4120Red Hat Product Security has rated this update as having a security impac ...
Synopsis Important: Red Hat Single Sign-On 764 security update on RHEL 9 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 764 packages are now available for Red Hat Enterprise Linux 9Red Hat ...
Synopsis Important: Red Hat Single Sign-On 764 security update on RHEL 8 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 764 packages are now available for Red Hat Enterprise Linux 8Red Hat ...
Synopsis Important: Red Hat Single Sign-On 764 security update on RHEL 7 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 764 packages are now available for Red Hat Enterprise Linux 7Red Hat ...
Synopsis Important: Red Hat Single Sign-On 764 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 76 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...