[MAVEN:GHSA-F5H4-WMP5-XHG6] Client Spoofing within the Keycloak Device Authorisation Grant

Severity Low
Affected Packages 2
Fixed Packages 2
CVEs 1

Under certain pre-conditions the vulnerability allows an attacker to spoof parts of the device flow and use a device_code to retrieve an access token for other OAuth clients.

ID
MAVEN:GHSA-F5H4-WMP5-XHG6
Severity
low
URL
https://github.com/advisories/GHSA-f5h4-wmp5-xhg6
Published
2023-06-30T20:29:25
(14 months ago)
Modified
2023-12-21T16:40:06
(9 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 21.1.2
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 21.1.2
Affected pkg:maven/org.keycloak/keycloak-server-spi-private org.keycloak keycloak-server-spi-private < 21.1.2
Fixed pkg:maven/org.keycloak/keycloak-server-spi-private org.keycloak keycloak-server-spi-private = 21.1.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...