#VU72725 Authentication bypass using an alternate path or channel in Keycloak - CVE-2023-0264
Published: March 2, 2023 / Updated: May 31, 2024
Keycloak
Keycloak
Description
The vulnerability allows a remote user to impersonate application users.
The vulnerability exists due to an error when handling authentication requests in the OpenID Connect user authentication. A remote authenticated user who can obtain a certain piece of info from a victim's user request from the same realm can use that data to impersonate the victim and generate new session tokens.