CVE-2023-3597

MEDIUM5.0EPSS 0.09%

Keycloak secondary factor bypass in step-up authentication

Published: 4/17/2024Modified: 2/4/2026

Description

Keycloak does not correctly validate its client step-up authentication. A password-authed attacker could use this flaw to register a false second auth factor, alongside the existing one, to a targeted account. The second factor then permits step-up authentication.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.0CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

References (9)