CVE-2023-0657: Red Hat Build Of Keycloak 22
Low severity, CVSS 3.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.
Affected products
- Red Hat Red Hat Build Of Keycloak 22: before 22.0.10-1 (fixed in 22.0.10-1); before 22-13 (fixed in 22-13); before 22-16 (fixed in 22-16)
- Red Hat Red Hat Build Of Keycloak 22.0.10
- Red Hat Red Hat Single Sign-On 7
Published 2024-11-17. Last modified 2026-06-17.