CVE-2023-0264
04.08.2023, 18:15
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | keycloak | 𝑥 < 18.0.6 |
| redhat | single_sign-on | 𝑥 < 7.6.2 |
| redhat | openshift_container_platform | 4.9 |
| redhat | openshift_container_platform | 4.10 |
| redhat | openshift_container_platform_for_ibm_linuxone | 4.9 |
| redhat | openshift_container_platform_for_ibm_linuxone | 4.10 |
| redhat | openshift_container_platform_ibm_z_systems | 4.9 |
| redhat | openshift_container_platform_ibm_z_systems | 4.10 |
| redhat | single_sign-on | 𝑥 < 7.6.2 |
| redhat | single_sign-on | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration