« Volver al listado

CVE-2023-3597

Estado: AplazadaMedia (5)—

A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication factor along with an existing one and bypass authentication.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-3597",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-3597",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-02T15:08:53.952771Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "22.0.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.0.0",
              "lessThan": "24.0.3",
              "versionType": "semver"
            }
          ],
          "packageName": "keycloak",
          "collectionURL": "https://www.keycloak.org/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22.0.10-1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22-13",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22-16",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22.0.10",
          "packageName": "keycloak",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:red_hat_single_sign_on:7.6"
          ],
          "vendor": "Red Hat",
          "product": "RHSSO 7.6.8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-04-25T13:15:50.523",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1866",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1867",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1868",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-3597",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2221760",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1867",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1868",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-3597",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2221760",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication factor along with an existing one and bypass authentication."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en Keycloak, donde no valida correctamente la autenticación incremental de su cliente en org.keycloak.authentication. Esta falla permite que un usuario remoto autenticado con una contraseña registre un segundo factor de autenticación falso junto con uno existente y omita la autenticación."
    }
  ],
  "lastModified": "2026-06-17T06:14:26.010",
  "sourceIdentifier": "secalert@redhat.com"
}