PT-2024-14908 · Red Hat · Red Hat Enterprise Application Platform 8+1

Rohit Keshri

·

Published

2024-04-09

·

Updated

2024-06-18

·

CVE-2023-6236

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Application Platform 8 JBoss EAP (affected versions not specified)
Description A flaw was found in the software when an OIDC app that serves multiple tenants attempts to access the second tenant. The issue arises because the software should prompt the user to log in again since the second tenant is secured with a different OIDC configuration. The underlying problem is in OidcSessionTokenStore when determining if a cached token should be used or not. This logic needs to be updated to take into account the new provider-url option in addition to the realm option.
Recommendations For Red Hat Enterprise Application Platform 8, update the logic in OidcSessionTokenStore to consider the provider-url option along with the realm option. For JBoss EAP, update the logic in OidcSessionTokenStore to consider the provider-url option along with the realm option. As a temporary workaround, consider disabling the use of cached tokens in OidcSessionTokenStore until a patch is available.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-6236
GHSA-JPMX-996V-48FM
RHSA-2024:3580
RHSA-2024:3581

Affected Products

Jboss Eap
Red Hat Enterprise Application Platform 8