VDB
Sign up
HIGH8.7

GHSA-9g98-5mj6-f9mv

Keycloak vulnerable to user impersonation via stolen UUID code

Quick fix

GHSA-9g98-5mj6-f9mv — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>21.0.1</version> for org.keycloak:keycloak-services

Details

Keycloak's OpenID Connect user authentication was found to incorrectly authenticate requests. An authenticated attacker who could also obtain a certain piece of info from a user request, from a victim within the same realm, could use that data to impersonate the victim and generate new session tokens.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 21.0.1
Fix# pom.xml: bump <version>21.0.1</version> for org.keycloak:keycloak-services

References