CVE-2023-4918
All users and clients with proper rights and roles are able to read users attributes, allowing a malicious user with minimal access to retrieve the users passwords in clear text, jeopardizing their environment.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. All users and clients with proper rights and roles are able to read users attributes, allowing a malicious user with minimal access to retrieve the users passwords in clear text, jeopardizing their environment.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-256, CWE-319
- Affected
- redhat/keycloak
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2023-4918Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2238588Issue Tracking, Vendor Advisory
- https://github.com/keycloak/keycloak/security/advisories/GHSA-5q66-v53q-pm35Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-4918Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2238588Issue Tracking, Vendor Advisory
- https://github.com/keycloak/keycloak/security/advisories/GHSA-5q66-v53q-pm35Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.