CVE-2023-0091

A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:36

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Keycloak, donde no verificó adecuadamente los tokens de los clientes para detectar una posible revocación en su flujo de credenciales de cliente. Esta falla permite a un atacante acceder o modificar información potencialmente confidencial.
References () https://access.redhat.com/security/cve/CVE-2023-0091 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2023-0091 - Vendor Advisory

22 Feb 2023, 17:07

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-13 06:15

Updated : 2024-11-21 07:36


NVD link : CVE-2023-0091

Mitre link : CVE-2023-0091

CVE.ORG link : CVE-2023-0091


JSON object : View

Products Affected

redhat

  • keycloak
  • single_sign-on
CWE
CWE-863

Incorrect Authorization