PT-2023-5395 · Keycloak+1 · Keycloak

Dasniko

·

Published

2023-09-12

·

Updated

2023-09-15

·

CVE-2023-4918

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description The issue is related to the transmission of data in plain text, allowing a remote attacker to gain access to user credentials. When a user registers through the registration flow, the password and password-confirm fields from the form are stored as regular user attributes. All users and clients with proper rights and roles can read these attributes, enabling a malicious user with minimal access to retrieve users' passwords in clear text. This jeopardizes the environment.
Recommendations For all affected versions, disable self-registration for users in all realms until a patch is available. As a temporary workaround, consider restricting access to user attributes to minimize the risk of exploitation. Avoid using the password and password-confirm fields in the registration flow until the issue is resolved.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06025
CVE-2023-4918
GHSA-5Q66-V53Q-PM35

Affected Products

Keycloak