Impact
A flaw in Keycloak's Pushed Authorization Request (PAR) handling allows an attacker to bypass the single‑use requirement for the pushed request URI when the silent authentication path (prompt=none) is invoked. This flaw falls under Missing Authorization Control (CWE‑862). The bypass causes the authorization flow to skip steps that normally enforce that a request URI may be used only once. As a result, an attacker who knows or can guess a previously used URI can obtain multiple authorization codes for a user who is already signed in, violating FAPI‑2 security rules.
Affected Systems
Red Hat Build of Keycloak and Red Hat Single Sign‑On 7 are listed as affected products. No specific version ranges are provided in the data, so any deployment of these products that has not been patched or upgraded is at risk. The CPE identifiers indicate the affected applications are the Red Hat Build of Keycloak and the Red Hat Single Sign‑On 7 product bundle.
Risk and Exploitability
The CVSS base score of 4.2 indicates moderate impact, and the EPSS score is not available, so current exploitation likelihood is unknown. The vulnerability is not listed in CISA's KEV catalog, suggesting no widespread known exploitation yet. The likely attack vector is a malicious client that initiates a PAR with prompt=none against a user who is already authenticated; the attacker would then capture multiple authorization codes. No additional prerequisites such as administrator credentials or network access are required beyond the ability to trigger the signed‑in user flow.
OpenCVE Enrichment