CVE Published: 21/12/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: redhat |
Vendor: Red Hat |
Product: Red Hat Single Sign-On 7 Status : PUBLISHED
CVE-2023-2585 Description
Keycloak\'s device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.