[MAVEN:GHSA-7FPJ-9HR8-28VH] Keycloak vulnerable to impersonation via logout token exchange

Severity Low
Affected Packages 2
Fixed Packages 2
CVEs 1

Keycloak was found to not properly enforce token types when validating signatures locally. An authenticated attacker could use this flaw to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

Package Affected Version
pkg:maven/org.keycloak/keycloak-services >= 23.0.0, < 24.0.3
pkg:maven/org.keycloak/keycloak-services < 22.0.10
ID
MAVEN:GHSA-7FPJ-9HR8-28VH
Severity
low
URL
https://github.com/advisories/GHSA-7fpj-9hr8-28vh
Published
2024-04-17T18:25:59
(5 months ago)
Modified
2024-04-17T18:26:00
(5 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services >= 23.0.0 < 24.0.3
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 24.0.3
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 22.0.10
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 22.0.10
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...