Impact
A flaw in the Conditional OTP authenticator of Keycloak enables an attacker who possesses a user’s password to bypass the one‑time password step by sending a specially crafted HTTP header that is not verified to originate from a trusted source. The vulnerability arises from the OTP skip‑header policy being evaluated against untrusted proxy headers, allowing an attacker to skip the second‑factor requirement and gain access without additional authentication.
Affected Systems
The issue affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7, as documented by the vendor. No specific version ranges are provided in the advisory, so all affected installations that employ the conditional OTP feature must verify whether they are running a patched build.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that the exploitation probability may not be high at present. However, the attack still requires possession of the user password and the ability to supply HTTP headers, implying that an attacker who has compromised credentials can elevate their privileges by manipulating request headers. Because no official workaround is available, the risk remains until a patch is applied.
OpenCVE Enrichment