Impact
The vulnerability is an omission in the Standard Token Exchange V2 feature of Keycloak; it fails to enforce the mutual TLS holder‑of‑key binding that normally restricts a token to the client that requested it. An attacker who has compromised client credentials can obtain a standard, unrestricted token that may be used outside the intended trusting relationship, potentially granting the attacker privileges or access otherwise denied.
Affected Systems
The affected products are Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. Specific version information is not provided in the advisory.
Risk and Exploitability
The CVSS score of 6.8 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires the attacker to first gain client credentials and then invoke the vulnerable token exchange endpoint; no additional access or code execution is required beyond those compromised credentials.
OpenCVE Enrichment