« Volver al listado

CVE-2023-0657

Estado: AplazadaBaja (3.4)—

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-0657",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-0657",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-17T16:18:32.777591Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.4,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "22.0.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.0.0",
              "lessThan": "24.0.3",
              "versionType": "semver"
            }
          ],
          "packageName": "keycloak",
          "collectionURL": "https://github.com/keycloak/keycloak",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22.0.10-1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22-13",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22-16",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22.0.10",
          "packageName": "keycloak",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:red_hat_single_sign_on:7"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Single Sign-On 7",
          "packageName": "keycloak",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-11-17T11:15:05.300",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1867",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1868",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-0657",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2166728",
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-273"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en Keycloak. Este problema ocurre debido a la aplicación incorrecta de tipos de tokens al validar firmas localmente. Esto podría permitir que un atacante autenticado intercambie un token de cierre de sesión por un token de acceso y posiblemente obtenga acceso a datos fuera de los permisos aplicados."
    }
  ],
  "lastModified": "2026-06-17T05:26:01.560",
  "sourceIdentifier": "secalert@redhat.com"
}