CVE-2023-0091

LOW

Keycloak - Incorrect Authorization in Client Credential Flow

Title source: llm
STIX 2.1

Description

A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

References (1)

Core 1

Scores

CVSS v3 3.8
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
org.keycloak/keycloak-core 0 - 20.0.3Maven
redhat/keycloak
Published Jan 13, 2023
Tracked Since Feb 18, 2026