keycloak: user impersonation via stolen uuid code
Published Aug 4, 2023
8.7
HIGHCVSS 3.1
EPSS 1.27%
Description
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
Affected products
-
- Version 18.0.6StatusaffectedConstraints<18.0.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Redhat.com | Keycloak | unaffected |
|
Configuration 2
- < 7.6.2
Running on/with
- 7.0
- 8.0
- 9.0
Configuration 3
- 4.9
- 4.10
- 4.9
- 4.10
- 4.9
- 4.10
- < 7.6.2
Running on/with
- 8.0
Configuration 4
- n/a
No data.
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-20
Fixed · RHSA-2023:1047
Red Hat Single Sign-On 7
rh-sso7-keycloak
Fixed · RHSA-2023:1049
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso
Fixed · RHSA-2023:1043
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso
Fixed · RHSA-2023:1044
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso
Fixed · RHSA-2023:1045
Red Hat A-MQ Online
keycloak-services
Not affected
Red Hat JBoss Enterprise Application Platform 6
keycloak-services
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-20 | Fixed | RHSA-2023:1047 |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Fixed | RHSA-2023:1049 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso | Fixed | RHSA-2023:1043 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso | Fixed | RHSA-2023:1044 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso | Fixed | RHSA-2023:1045 |
| Red Hat A-MQ Online | keycloak-services | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-services | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-0264 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2160585 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0967 Advisory
- https://github.com/advisories/GHSA-9g98-5mj6-f9mv Advisory
- https://github.com/keycloak/keycloak/commit/ec8109112e67208c13e13f6d1f8706a5a3ba8d4c
- https://github.com/keycloak/keycloak/security/advisories/GHSA-9g98-5mj6-f9mv
- https://nvd.nist.gov/vuln/detail/CVE-2023-0264
- https://www.cve.org/CVERecord?id=CVE-2023-0264
Change history (0)
No recorded changes yet.