Skip to content

Secondary factor bypass in step-up authentication

Moderate
abstractj published GHSA-4f53-xh3v-g8x4 Apr 17, 2024

Package

maven org.keycloak.authentication (Maven)

Affected versions

< 22.0.10, < 24.0.3

Patched versions

22.0.10, 24.0.3

Description

Keycloak does not correctly validate its client step-up authentication. A password-authed attacker could use this flaw to register a false second auth factor, alongside the existing one, to a targeted account. The second factor then permits step-up authentication.

Severity

Moderate

CVE ID

CVE-2023-3597

Credits