First published: Sat Dec 23 2023(Updated: )
An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Keycloak Authenticator | <1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49594 is classified as an information disclosure vulnerability, which may expose sensitive information.
To address CVE-2023-49594, upgrade the DuoUniversalKeycloakAuthenticator plugin to version 1.0.8 or later.
CVE-2023-49594 affects versions prior to 1.0.8 of the DuoUniversalKeycloakAuthenticator plugin.
CVE-2023-49594 is an information disclosure vulnerability impacting the authentication process.
Users of Keycloak utilizing the DuoUniversalKeycloakAuthenticator plugin versions earlier than 1.0.8 are impacted by CVE-2023-49594.