← Back

CVE-2023-0091

nvd nist
Published: Jan 13, 2023Modified: Apr 9, 2025

JSON object

Loading...
3.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.2 / Impact: 2.5
Source: NVD

Description

A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

Affected (1)

Products: Redhat: Keycloak
1 product
Keycloak
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Redhat
Single Sign On
Version 7.0

References (2)

Source: secalert@redhat.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.