VDB
BDU%3A2024-02081
BDU%3A2024-02081
PUBLISHED
CVSS 6.5 MEDIUM
Уязвимость программного средства для управления идентификацией и доступом Keycloak, связанная с недостатками процедуры аутентификации, позволяющая нарушителю перехватить активный сеанс
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat build of Keycloak 22 | 22-16 |
| 0, 0 | ||
| Red Hat | Red Hat build of Keycloak 22.0.10 | |
| Red Hat | Red Hat build of Keycloak 22 | 22.0.10-1 |
| Red Hat Inc. | Red Hat Single Sign-On, Red Hat Build of Keycloak | |
| Red Hat | Red Hat Single Sign-On 7 | |
| Red Hat | Red Hat build of Keycloak 22 | 22-13 |
Timeline
- Feb 21, 2024 PoC Published
- Mar 18, 2024 CVE Published
- May 31, 2026 Distribution Patch
- May 31, 2026 Distribution Patch
- May 31, 2026 Security Advisory
- May 31, 2026 Security Advisory
References
- https://security.snyk.io/vuln/SNYK-RHEL9-RHSSO7KEYCLOAKSERVER-6256338 url
- https://access.redhat.com/security/cve/cve-2023-6787 url
- https://security.snyk.io/vuln/SNYK-JAVA-ORGKEYCLOAK-6291711 url
- https://security.snyk.io/vuln/SNYK-RHEL7-RHSSO7KEYCLOAKSERVER-6261417 url
- RHSA-2024:1867 vendor-advisory
- RHSA-2024:1868 vendor-advisory
- https://github.com/keycloak/keycloak/security/advisories/GHSA-c9h6-v78w-52wj url
- https://access.redhat.com/security/cve/CVE-2023-6787 vdb
- RHBZ#2254375 issue
- https://security.snyk.io/vuln/SNYK-RHEL8-RHSSO7KEYCLOAKSERVER-6258884 url