Improper authorization control for web services In org.keycloak:keycloak-services
Description
Keycloak vulnerable to user impersonation via stolen UUID code Keycloak's OpenID Connect user authentication was found to incorrectly authenticate requests. An authenticated attacker who could also obtain a certain piece of info from a user request, from a victim within the same realm, could use that data to impersonate the victim and generate new session tokens.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 21.0.1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.