Impact
The keycloak-services component in Red Hat Build of Keycloak does not bind OAuth 2.0 authorization codes to the requesting client. An attacker who intercepts a code can modify it so that an attacker‑controlled client can redeem it, thereby obtaining an access token that represents the victim’s identity. This enables the attacker to impersonate the victim and access protected resources that the victim is authorized to use, thereby compromising confidentiality and integrity of the victim’s account. The description does not mention additional capabilities beyond this token acquisition; therefore, the impact is limited to unauthorized access via a compromised authorization flow.
Affected Systems
Affected products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. The flaw exists in the keycloak-services component across all builds of these products released prior to the advisory; no specific patch version is listed, so any installation from the time of the advisory may be impacted.
Risk and Exploitability
The CVSS score of 5.4 denotes a moderate severity risk. The EPSS score of < 1% indicates a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, meaning no publicly known exploits have been reported. The likely attack vector is interception of an authorization code over a network or on a compromised component; this inference is based on the requirement for code possession, which typically implies network access or a compromised middle‑box. Once the code is in an attacker’s hands, the complexity of modifying it is low because no special privileges are required.
OpenCVE Enrichment