CVE-2023-2585: Keycloak: client access via device auth request spoof
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authed admin into granting consent to a malicious OAuth client, or possible unauthorized access to an existing OAuth client.
Other sources
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.
Under certain pre-conditions the vulnerability allows an attacker to spoof parts of the device flow and use a devicecode to retrieve an access token for other OAuth clients.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2023-2585?
CVE-2023-2585 is considered a significant vulnerability due to its potential for client consent spoofing.
How do I fix CVE-2023-2585?
To remediate CVE-2023-2585, update to the specified secure versions of the affected software packages.
What types of systems are affected by CVE-2023-2585?
CVE-2023-2585 affects multiple versions of rh-sso7-keycloak and several Red Hat OpenShift Container Platform versions.
What are the implications of CVE-2023-2585?
Exploitation of CVE-2023-2585 could allow attackers to impersonate legitimate clients and manipulate admin consent processes.
Who should be notified about CVE-2023-2585?
System administrators and cybersecurity teams using affected versions of Keycloak should be notified to assess and implement fixes.