VDB
BDU%3A2023-05657
BDU%3A2023-05657
PUBLISHED
CVSS 4.699999809265137 MEDIUM
Уязвимость программного средства для управления идентификацией и доступом Keycloak, связанная с неправильно реализованной проверкой безопасности для стандартных элементов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
4.699999809265137
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | RHEL-8 based Middleware Containers | 7.6-24 |
| Red Hat | Red Hat Single Sign-On 7 | |
| Red Hat Inc. | Red Hat Single Sign-On, Red Hat Enterprise Linux, Keycloak | |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 9 | 0:18.0.8-1.redhat_00001.1.el9sso |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 7 | 0:18.0.8-1.redhat_00001.1.el7sso |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 8 | 0:18.0.8-1.redhat_00001.1.el8sso |
Timeline
- Sep 14, 2023 CVE Published
- Dec 21, 2023 PoC Published
- Dec 23, 2023 PoC Published
- Apr 27, 2026 Distribution Patch
- Apr 27, 2026 Distribution Patch
- Apr 27, 2026 Distribution Patch
- Apr 27, 2026 Distribution Patch
- Apr 27, 2026 Distribution Patch
- Apr 27, 2026 Security Advisory
- Apr 27, 2026 Security Advisory
- Apr 27, 2026 Security Advisory
- Apr 27, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2196335 url
- https://access.redhat.com/security/cve/cve-2023-2585 url
- https://github.com/advisories/GHSA-f5h4-wmp5-xhg6 url
- https://vuldb.com/?id.232442 url
- https://github.com/keycloak/keycloak/commit/04e6244c387a1bde86184635a0049537611e3915 advisory
- RHSA-2023:3883 vendor-advisory
- RHSA-2023:3884 vendor-advisory
- RHSA-2023:3885 vendor-advisory
- RHSA-2023:3888 vendor-advisory
- RHSA-2023:3892 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-2585 vdb