A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2023-08-04T17:09:27.693Z

Updated: 2023-08-04T17:09:27.693Z

Reserved: 2023-01-12T23:10:37.812Z


Link: CVE-2023-0264

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-08-04T18:15:11.090

Modified: 2023-08-14T18:14:02.440


Link: CVE-2023-0264

JSON object: View

cve-icon Redhat Information

No data.

CWE