Security Advisory

CVE-2023-2585

3.5
LOW

Vulnerability Description

Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.
Published Date December 21, 2023
Official Source NIST NVD Advisory