diff --git a/advisories/github-reviewed/2024/04/GHSA-7fpj-9hr8-28vh/GHSA-7fpj-9hr8-28vh.json b/advisories/github-reviewed/2024/04/GHSA-7fpj-9hr8-28vh/GHSA-7fpj-9hr8-28vh.json index 5cfac8e73e3..ab35363680d 100644 --- a/advisories/github-reviewed/2024/04/GHSA-7fpj-9hr8-28vh/GHSA-7fpj-9hr8-28vh.json +++ b/advisories/github-reviewed/2024/04/GHSA-7fpj-9hr8-28vh/GHSA-7fpj-9hr8-28vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fpj-9hr8-28vh", - "modified": "2024-04-17T18:25:59Z", + "modified": "2024-11-18T17:28:39Z", "published": "2024-04-17T18:25:59Z", "aliases": [ "CVE-2023-0657" @@ -9,7 +9,10 @@ "summary": "Keycloak vulnerable to impersonation via logout token exchange", "details": "Keycloak was found to not properly enforce token types when validating signatures locally. An authenticated attacker could use this flaw to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ { @@ -56,6 +59,26 @@ "type": "WEB", "url": "https://github.com/keycloak/keycloak/security/advisories/GHSA-7fpj-9hr8-28vh" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0657" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1867" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1868" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-0657" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2166728" + }, { "type": "PACKAGE", "url": "https://github.com/keycloak/keycloak" @@ -63,6 +86,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-273", "CWE-284", "CWE-287", "CWE-290", @@ -71,6 +95,6 @@ "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-04-17T18:25:59Z", - "nvd_published_at": null + "nvd_published_at": "2024-11-17T11:15:05Z" } } \ No newline at end of file