CVE-2023-2585

HIGHCVSS 8.1/10EPSS 0.59%

Last modified

CVE-2023-2585 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.

Description

Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

EPSS Probability
0.59%

43.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RedhatSingle Sign-On7.6
RedhatOpenshift Container Platform4.11
RedhatOpenshift Container Platform4.12
RedhatOpenshift Container Platform For Ibm Z4.9
RedhatOpenshift Container Platform For Ibm Z4.10
RedhatOpenshift Container Platform For Linuxone4.9
RedhatOpenshift Container Platform For Linuxone4.10
RedhatOpenshift Container Platform For Power4.9
RedhatOpenshift Container Platform For Power4.10
RedhatSingle Sign-OnAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-2585?
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.
How severe is CVE-2023-2585?
CVE-2023-2585 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.59% probability of exploitation in the next 30 days.
How do I fix CVE-2023-2585?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-2585?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST