A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-3427 Duplicate Advisory: WildFly Elytron OpenID Connect Client Extension authorization code injection attack
Github GHSA Github GHSA GHSA-5565-3c98-g6jc WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack
Fixes

Solution

No solution given by the vendor.


Workaround

Currently, no mitigation is currently available for this vulnerability.

History

Thu, 02 Oct 2025 12:15:00 +0000


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00037}

epss

{'score': 0.00042}


Thu, 17 Apr 2025 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8
References

Tue, 10 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 09 Dec 2024 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.
Title Elytron-oidc-client: oidc authorization code injection
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Enterprise Application Platform
Weaknesses CWE-345
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Enterprise Application Platform
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-11-11T16:07:38.116Z

Reserved: 2024-12-09T16:33:36.277Z

Link: CVE-2024-12369

cve-icon Vulnrichment

Updated: 2024-12-10T15:29:46.377Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-09T21:15:08.203

Modified: 2025-10-02T12:15:28.397

Link: CVE-2024-12369

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-12-09T00:00:00Z

Links: CVE-2024-12369 - Bugzilla

cve-icon OpenCVE Enrichment

No data.