Back

HIGH

keycloak: user impersonation via stolen uuid code

Published Aug 4, 2023

Description

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 4, 2023
Updated Aug 2, 2024
Reserved Jan 12, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 28, 2023
ENISA EUVD
Assigner redhat
Published Aug 4, 2023
Updated Aug 2, 2024
Exploited since n/a
EUVD-2023-0967 GHSA-9G98-5MJ6-F9MV