CVE-2023-0264
04.08.2023, 18:15
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | keycloak | 𝑥 < 18.0.6 |
redhat | single_sign-on | 𝑥 < 7.6.2 |
redhat | openshift_container_platform | 4.9 |
redhat | openshift_container_platform | 4.10 |
redhat | openshift_container_platform_for_ibm_linuxone | 4.9 |
redhat | openshift_container_platform_for_ibm_linuxone | 4.10 |
redhat | openshift_container_platform_ibm_z_systems | 4.9 |
redhat | openshift_container_platform_ibm_z_systems | 4.10 |
redhat | single_sign-on | 𝑥 < 7.6.2 |
redhat | single_sign-on | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration