HIGH8.7
GHSA-9g98-5mj6-f9mv
Keycloak vulnerable to user impersonation via stolen UUID code
Quick fix
GHSA-9g98-5mj6-f9mv — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.
# pom.xml: bump <version>21.0.1</version> for org.keycloak:keycloak-servicesDetails
Keycloak's OpenID Connect user authentication was found to incorrectly authenticate requests. An authenticated attacker who could also obtain a certain piece of info from a user request, from a victim within the same realm, could use that data to impersonate the victim and generate new session tokens.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.keycloak:keycloak-services
Introduced in:
0Fixed in: 21.0.1Fix
# pom.xml: bump <version>21.0.1</version> for org.keycloak:keycloak-servicesReferences
- https://github.com/keycloak/keycloak/security/advisories/GHSA-9g98-5mj6-f9mv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-0264[ADVISORY]
- https://github.com/keycloak/keycloak/commit/ec8109112e67208c13e13f6d1f8706a5a3ba8d4c[WEB]
- https://access.redhat.com/security/cve/CVE-2023-0264[WEB]
- https://github.com/keycloak/keycloak[PACKAGE]