It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2017-10-26T17:00:00Z

Updated: 2024-09-16T18:48:51.709Z

Reserved: 2017-08-01T00:00:00

Link: CVE-2017-12160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-10-26T17:29:00.297

Modified: 2024-11-21T03:08:57.410

Link: CVE-2017-12160

cve-icon Redhat

Severity : Low

Publid Date: 2017-10-17T00:00:00Z

Links: CVE-2017-12160 - Bugzilla