CVE Database · CVE-2023-0091
CVSS v3.1
3.8
EPSS
0.47%
Published
Jan 13, 2023
Modified
Apr 9, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:NWeaknesses (CWE)
References (2)