MEDIUM 5.0 Maven

Keycloak secondary factor bypass in step-up authentication

GHSA-4f53-xh3v-g8x4 · CVE-2023-3597

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Keycloak does not correctly validate its client step-up authentication. A password-authed attacker could use this flaw to register a false second auth factor, alongside the existing one, to a targeted account. The second factor then permits step-up authentication.

Ready to move

Start Securing

Free, no credit card | First findings in minutes