CVE-2023-0657

Published at:
2024-11-17T11:15:05.300

Global infos:

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

CVE Status: Awaiting Analysis

References:

  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • Metrics:

    AttributeValue
    Attack ComplexityHIGH
    Attack VectorADJACENT_NETWORK
    Availability ImpactNONE
    Base Score3.4
    Base SeverityLOW
    Confidentiality ImpactLOW
    Integrity ImpactLOW
    Privileges RequiredLOW
    ScopeUNCHANGED
    User InteractionREQUIRED
    Vector StringCVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
    Exploitability Score0.9
    Impact Score2.5
    Source[email protected]
    TypePrimary

    Links:

    Exploit-db
    Github