CVE-2023-49594

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:michaelkelly:duouniversalkeycloakauthenticator:*:*:*:*:*:keycloak:*:*

History

21 Nov 2024, 08:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 4.5
References () https://github.com/instipod/DuoUniversalKeycloakAuthenticator/releases/tag/1.0.8 - Release Notes () https://github.com/instipod/DuoUniversalKeycloakAuthenticator/releases/tag/1.0.8 - Release Notes
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1907 - Exploit, Third Party Advisory () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1907 - Exploit, Third Party Advisory

17 Jan 2024, 21:15

Type Values Removed Values Added
Summary (en) An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability. (en) An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.
Summary (es) Existe una vulnerabilidad de divulgación de información en la funcionalidad de desafío de instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. Una solicitud HTTP especialmente manipulada puede dar lugar a la divulgación de información confidencial. Un usuario que inicia sesión en Keycloak utilizando el complemento DuoUniversalKeycloakAuthenticator desencadena esta vulnerabilidad. (es) Existe una vulnerabilidad de divulgación de información en la funcionalidad de desafío del complemento instipod DuoUniversalKeycloakAuthenticator 1.0.7. Una solicitud HTTP especialmente manipulada puede dar lugar a la divulgación de información confidencial. Un usuario que inicia sesión en Keycloak utilizando el complemento DuoUniversalKeycloakAuthenticator desencadena esta vulnerabilidad.

03 Jan 2024, 20:40

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 4.5
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:michaelkelly:duouniversalkeycloakauthenticator:*:*:*:*:*:keycloak:*:*
First Time Michaelkelly
Michaelkelly duouniversalkeycloakauthenticator
References () https://github.com/instipod/DuoUniversalKeycloakAuthenticator/releases/tag/1.0.8 - () https://github.com/instipod/DuoUniversalKeycloakAuthenticator/releases/tag/1.0.8 - Release Notes
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1907 - () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1907 - Exploit, Third Party Advisory
Summary
  • (es) Existe una vulnerabilidad de divulgación de información en la funcionalidad de desafío de instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. Una solicitud HTTP especialmente manipulada puede dar lugar a la divulgación de información confidencial. Un usuario que inicia sesión en Keycloak utilizando el complemento DuoUniversalKeycloakAuthenticator desencadena esta vulnerabilidad.

24 Dec 2023, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1907', 'source': 'talos-cna@cisco.com'}

23 Dec 2023, 21:15

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1907 -

23 Dec 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-23 20:15

Updated : 2024-11-21 08:33


NVD link : CVE-2023-49594

Mitre link : CVE-2023-49594

CVE.ORG link : CVE-2023-49594


JSON object : View

Products Affected

michaelkelly

  • duouniversalkeycloakauthenticator
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data

NVD-CWE-noinfo