Client access via device auth request spoof
CVE-2023-2585
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 21 December 2023
What is CVE-2023-2585?
Keycloak's device authorization grant has a flaw in its validation process, which allows attackers to potentially spoof requests. By leveraging this vulnerability, an attacker could manipulate the consent flow, leading authorization administrators to unknowingly approve access for a malicious OAuth client. This can result in unauthorized access to sensitive information or systems that rely on valid OAuth client consent.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat Single Sign-On 7.6 for RHEL 7 0:18.0.8-1.redhat_00001.1.el7sso
Red Hat Single Sign-On 7.6 for RHEL 8 0:18.0.8-1.redhat_00001.1.el8sso
Red Hat Single Sign-On 7.6 for RHEL 9 0:18.0.8-1.redhat_00001.1.el9sso
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved