CVE-2024-4540

A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly leading to an information disclosure vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 09:43

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Keycloak en las solicitudes de autorización push (PAR) de OAuth 2.0. Se descubrió que los parámetros proporcionados por el cliente estaban incluidos en texto plano en la cookie KC_RESTART devuelta por la respuesta HTTP del servidor de autorización a una solicitud de autorización `request_uri`, lo que posiblemente conduzca a una vulnerabilidad de divulgación de información.
References () https://access.redhat.com/errata/RHSA-2024:3566 - () https://access.redhat.com/errata/RHSA-2024:3566 -
References () https://access.redhat.com/errata/RHSA-2024:3567 - () https://access.redhat.com/errata/RHSA-2024:3567 -
References () https://access.redhat.com/errata/RHSA-2024:3568 - () https://access.redhat.com/errata/RHSA-2024:3568 -
References () https://access.redhat.com/errata/RHSA-2024:3570 - () https://access.redhat.com/errata/RHSA-2024:3570 -
References () https://access.redhat.com/errata/RHSA-2024:3572 - () https://access.redhat.com/errata/RHSA-2024:3572 -
References () https://access.redhat.com/errata/RHSA-2024:3573 - () https://access.redhat.com/errata/RHSA-2024:3573 -
References () https://access.redhat.com/errata/RHSA-2024:3574 - () https://access.redhat.com/errata/RHSA-2024:3574 -
References () https://access.redhat.com/errata/RHSA-2024:3575 - () https://access.redhat.com/errata/RHSA-2024:3575 -
References () https://access.redhat.com/errata/RHSA-2024:3576 - () https://access.redhat.com/errata/RHSA-2024:3576 -
References () https://access.redhat.com/security/cve/CVE-2024-4540 - () https://access.redhat.com/security/cve/CVE-2024-4540 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2279303 - () https://bugzilla.redhat.com/show_bug.cgi?id=2279303 -

03 Jun 2024, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:3566 -
  • () https://access.redhat.com/errata/RHSA-2024:3567 -
  • () https://access.redhat.com/errata/RHSA-2024:3568 -
  • () https://access.redhat.com/errata/RHSA-2024:3570 -
  • () https://access.redhat.com/errata/RHSA-2024:3572 -
  • () https://access.redhat.com/errata/RHSA-2024:3573 -
  • () https://access.redhat.com/errata/RHSA-2024:3574 -
  • () https://access.redhat.com/errata/RHSA-2024:3575 -
  • () https://access.redhat.com/errata/RHSA-2024:3576 -

03 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-03 16:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4540

Mitre link : CVE-2024-4540

CVE.ORG link : CVE-2024-4540


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor