Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.0 Maven

Keycloak secondary factor bypass in step-up authentication

GHSA-4f53-xh3v-g8x4 · CVE-2023-3597

Published · Modified

Description

Keycloak does not correctly validate its client step-up authentication. A password-authed attacker could use this flaw to register a false second auth factor, alongside the existing one, to a targeted account. The second factor then permits step-up authentication.

Ready to move

Start Securing

Free, no credit card | First findings in minutes