Keycloak: secondary factor bypass in step-up authentication
Published Apr 25, 2024
5.0
MEDIUMCVSS 3.1
EPSS 0.60%
Description
A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication factor along with an existing one and bypass authentication.
Affected products
No data.
No data.
No data.
RHSSO 7.6.8
n/a
Fixed · RHSA-2024:1866
Red Hat build of Keycloak 22
rhbk/keycloak-operator-bundle:22.0.10-1
Fixed · RHSA-2024:1867
Red Hat build of Keycloak 22
rhbk/keycloak-rhel9-operator:22-16
Fixed · RHSA-2024:1867
Red Hat build of Keycloak 22
rhbk/keycloak-rhel9:22-13
Fixed · RHSA-2024:1867
Red Hat build of Keycloak 22.0.10
keycloak
Fixed · RHSA-2024:1868
| Product | Package | State | Advisory |
|---|---|---|---|
| RHSSO 7.6.8 | n/a | Fixed | RHSA-2024:1866 |
| Red Hat build of Keycloak 22 | rhbk/keycloak-operator-bundle:22.0.10-1 | Fixed | RHSA-2024:1867 |
| Red Hat build of Keycloak 22 | rhbk/keycloak-rhel9-operator:22-16 | Fixed | RHSA-2024:1867 |
| Red Hat build of Keycloak 22 | rhbk/keycloak-rhel9:22-13 | Fixed | RHSA-2024:1867 |
| Red Hat build of Keycloak 22.0.10 | keycloak | Fixed | RHSA-2024:1868 |
No package ranges for this CVE.
Remediation
Red Hat statement
Note that exploitation of this flaw requires several factors to be successful. The attacker must already have valid credentials within the system, without which there is no vulnerability, and the application must be configured to use the step-up flow, which is the only aspect of authentication bypassed by this flaw; the name and password restriction function as expected. Further, the impact effects of this flaw are limited to user-level and do not affect the system as a whole. For this reason, Red Hat Product Security has assessed this flaw to be Moderate security impact.
References (11)
- https://access.redhat.com/errata/RHSA-2024:1866 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1867 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1868 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-3597 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2221760 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1090 Advisory
- https://github.com/advisories/GHSA-4f53-xh3v-g8x4 Advisory
- https://github.com/keycloak/keycloak/commit/aa634aee882892960a526e49982806e103c8a432
- https://github.com/keycloak/keycloak/security/advisories/GHSA-4f53-xh3v-g8x4
- https://nvd.nist.gov/vuln/detail/CVE-2023-3597
- https://www.cve.org/CVERecord?id=CVE-2023-3597
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:1866 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:1867 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:1868 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2023-3597 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2221760 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1090 | Advisory | |
| https://github.com/advisories/GHSA-4f53-xh3v-g8x4 | Advisory | |
| https://github.com/keycloak/keycloak/commit/aa634aee882892960a526e49982806e103c8a432 | ||
| https://github.com/keycloak/keycloak/security/advisories/GHSA-4f53-xh3v-g8x4 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-3597 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-3597 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub