VDB
BDU%3A2023-05658
BDU%3A2023-05658
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость программного средства для управления идентификацией и доступом Keycloak, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | RHEL-8 based Middleware Containers | 7.6-24 |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 7 | 0:18.0.8-1.redhat_00001.1.el7sso |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 9 | 0:18.0.8-1.redhat_00001.1.el9sso |
| Red Hat Inc. | Red Hat Single Sign-On, Red Hat Enterprise Linux, Keycloak | |
| Red Hat | Red Hat Single Sign-On 7.6 for RHEL 8 | 0:18.0.8-1.redhat_00001.1.el8sso |
| Red Hat | Red Hat Single Sign-On 7 |
Timeline
- Sep 14, 2023 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
References
- https://access.redhat.com/security/cve/cve-2023-2422 url
- https://vuldb.com/ru/?id.232441 url
- https://github.com/advisories/GHSA-3qh5-qqj2-c78f url
- https://www.cybersecurity-help.cz/vdb/SB2023062847 url
- https://github.com/keycloak/keycloak/security/advisories/GHSA-3qh5-qqj2-c78f advisory
- https://github.com/keycloak/keycloak/commit/5c6c55945a384bfd82e51283096204dcb6f63d91 advisory
- RHSA-2023:3883 vendor-advisory
- RHSA-2023:3884 vendor-advisory
- RHSA-2023:3885 vendor-advisory
- RHSA-2023:3888 vendor-advisory
- RHSA-2023:3892 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-2422 vdb
- RHBZ#2191668 issue