216.73.217.22

CVE-2023-0657

· Published 17/11/2024 11:15 · Modified 18/11/2024 17:11

Labels: CVE-2023-0657 2024-11-17CVE-2023-0657CWE-273[email protected]

Essential information

Published
17/11/2024 11:15
Modified
18/11/2024 17:11
Author
Creator
CVSS
3.4 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

CVSS metrics

Description

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References