Authorization Code Injection Vulnerability in RH SSO OIDC Adapter

CVE-2024-12369

4.2MEDIUM

Key Information

Vendor
Red Hat
Status
Red Hat Build Of Keycloak
Red Hat Jboss Enterprise Application Platform 7
Red Hat Jboss Enterprise Application Platform 8
Vendor
CVE Published:
9 December 2024

Summary

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

This issue was discovered by Olivier Rivat (Red Hat).
.