Impact
The flaw in the keycloak-services component causes OAuth 2.0 authorization codes to lack proper binding to the client that requested them. If an attacker intercepts an authorization code, they can alter it so that a different client can redeem it, thereby obtaining access tokens that represent the victim’s identity. This can enable impersonation and subsequent unauthorized access to protected resources, compromising confidentiality and integrity of the victim’s accounts.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7, and Red Hat Data Grid 8. All affected products use the keycloak-services component, and the issue applies to the specific build identified in the Red Hat catalog. No specific patch version is listed, so any installation of these products from the time of the advisory is potentially impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity risk. The EPSS score of < 1% suggests that exploitation is unlikely in the short term. The vulnerability is not currently listed in the CISA KEV catalog, so no publicly known exploits have been reported. The attack vector involves intercepting an authorization code, which typically requires network-level access or a compromised network component. However, the absence of a binding allows an attacker to modify the code after interception, reducing the complexity required once the code is in hand.
OpenCVE Enrichment