REDHAT-BUG-2279303: Low severity Red Hat Keycloak vulnerability
A flaw was found in Keycloak in the OAuth 2.0 Pushed Authorization Requests (PAR). Client provided parameters were found to be included in plain text in the KCRESTART cookie returned by the authorization server's HTTP response to a requesturi authorization request. This could lead to an information disclosure vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2279303?
The severity of REDHAT-BUG-2279303 is critical due to the potential exposure of sensitive client parameters in plain text.
How do I fix REDHAT-BUG-2279303?
To fix REDHAT-BUG-2279303, you should upgrade to the latest patched version of Red Hat Keycloak as recommended by the security advisory.
What vulnerabilities does REDHAT-BUG-2279303 address?
REDHAT-BUG-2279303 addresses a flaw in the handling of OAuth 2.0 Pushed Authorization Requests that can lead to information exposure.
Who is affected by REDHAT-BUG-2279303?
REDHAT-BUG-2279303 affects users of Red Hat Keycloak utilizing the OAuth 2.0 Pushed Authorization Requests feature.
Is there a workaround for REDHAT-BUG-2279303?
There are no recommended workarounds for REDHAT-BUG-2279303, and the best course of action is to apply security updates.