Skip to content

Impersonation via logout token exchange

Low
abstractj published GHSA-7fpj-9hr8-28vh Apr 17, 2024

Package

maven org.keycloak.broker.oidc (Maven)

Affected versions

< 22.0.10, < 24.0.3

Patched versions

22.0.10, 24.0.3

Description

Keycloak was found to not properly enforce token types when validating signatures locally. An authenticated attacker could use this flaw to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

Severity

Low

CVE ID

CVE-2023-0657