CVE-2023-49594: Michaelkelly Duouniversalkeycloakauthenticator

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.

Affected products

  • Michaelkelly Duouniversalkeycloakauthenticator: before 1.0.8 (fixed in 1.0.8)

Published 2023-12-23. Last modified 2026-06-17.