CVE-2024-12369: Red Hat Build Of Keycloak
Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.
Affected products
- Red Hat Red Hat Build Of Keycloak
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 8: before 0:2.16.1-1.redhat_00001.1.el8eap (fixed in 0:2.16.1-1.redhat_00001.1.el8eap); before 0:1.80.0-1.redhat_00001.1.el8eap (fixed in 0:1.80.0-1.redhat_00001.1.el8eap); before 0:800.7.0-2.GA_redhat_00002.1.el8eap (fixed in 0:800.7.0-2.GA_redhat_00002.1.el8eap); before 0:6.2.35-1.Final_redhat_00001.1.el8eap (fixed in 0:6.2.35-1.Final_redhat_00001.1.el8eap); before 0:3.0.13-1.Final_redhat_00001.1.el8eap (fixed in 0:3.0.13-1.Final_redhat_00001.1.el8eap); before 0:3.0.1-1.redhat_00001.1.el8eap (fixed in 0:3.0.1-1.redhat_00001.1.el8eap); …
Published 2024-12-09. Last modified 2026-08-04.