CVE-2023-0264

CVSS v3.1 5 (Medium)
50% Progress
EPSS 0.05 % (19th)
0.05% Progress
Affected Products 6
Advisories 1

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.

Weaknesses
CWE-287
Improper Authentication
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2023-08-04 18:15:11
(13 months ago)
Updated Date
2023-08-14 18:14:02
(13 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Redhat Keycloak prior 18.0.6 version cpe:2.3:a:redhat:keycloak < 18.0.6

Configuration #2

AND
    CPE23 From Up To
OR  
  Redhat Single Sign-on prior 7.6.2 version cpe:2.3:a:redhat:single_sign-on < 7.6.2
OR  
  Running on/with
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0
OR  
  Running on/with
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
OR  
  Running on/with
  Redhat Enterprise Linux 9.0 cpe:2.3:o:redhat:enterprise_linux:9.0

Configuration #3

AND
    CPE23 From Up To
OR  
  Redhat Openshift Container Platform 4.9 cpe:2.3:a:redhat:openshift_container_platform:4.9
OR  
  Running on/with
  Redhat Openshift Container Platform 4.10 cpe:2.3:a:redhat:openshift_container_platform:4.10
OR  
  Running on/with
  Redhat Openshift Container Platform for Ibm Linuxone 4.9 cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.9
OR  
  Running on/with
  Redhat Openshift Container Platform for Ibm Linuxone 4.10 cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.10
OR  
  Running on/with
  Redhat Openshift Container Platform Ibm Z Systems 4.9 cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.9
OR  
  Running on/with
  Redhat Openshift Container Platform Ibm Z Systems 4.10 cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.10
OR  
  Running on/with
  Redhat Single Sign-on prior 7.6.2 version cpe:2.3:a:redhat:single_sign-on < 7.6.2
OR  
  Running on/with
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0

Configuration #4

    CPE23 From Up To
  Redhat Single Sign-on cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...