CVE-2023-3597: Red Hat Build Of Keycloak 22

Medium severity, CVSS 5.0. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication factor along with an existing one and bypass authentication.

Affected products

  • Red Hat Red Hat Build Of Keycloak 22: before 22.0.10-1 (fixed in 22.0.10-1); before 22-13 (fixed in 22-13); before 22-16 (fixed in 22-16)
  • Red Hat Red Hat Build Of Keycloak 22.0.10
  • Red Hat Rhsso 7.6.8

Published 2024-04-25. Last modified 2026-06-17.