CVE-2023-0264: High severity redhat keycloak vulnerability
A flaw was found in Keycloak's OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, Integrity, and availability.
Other sources
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
Keycloak's OpenID Connect user authentication was found to incorrectly authenticate requests. An authenticated attacker who could also obtain a certain piece of info from a user request, from a victim within the same realm, could use that data to impersonate the victim and generate new session tokens.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.6-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.6-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.6-1.redhat_00001.1.el9 - Upgrade
Upgrade
maven/org.keycloak:keycloak-servicesto a version that resolves this vulnerability.Fixed in 21.0.1 - Upgrade
Upgrade
redhat/keycloakto a version that resolves this vulnerability.Fixed in 18.0.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-0264?
CVE-2023-0264 is a vulnerability found in Keycloak's OpenID Connect user authentication that may incorrectly authenticate requests.
How does CVE-2023-0264 impact Keycloak?
CVE-2023-0264 allows an authenticated attacker to impersonate a victim and generate new session tokens by obtaining information from a user request within the same realm.
What is the severity level of CVE-2023-0264?
CVE-2023-0264 has a severity level of high with a score of 8.7.
How do I fix CVE-2023-0264 in Keycloak?
To fix CVE-2023-0264 in Keycloak, update to version 18.0.6 or higher.
Where can I find more information about CVE-2023-0264?
You can find more information about CVE-2023-0264 on the Redhat website at the following URLs: [URL1], [URL2], [URL3]