Back to directory
WRITEUP #1292

User impersonation via stolen UUID code in KeyCloak (CVE-2023-0264)

OAuthOIDCPrivilege escalationBroken authentication
byJordi Zayuelas i Muñoz
Program
Keycloak
Published
Apr 14, 2023
Added to HackDex
Apr 28, 2023
Read Full Writeuphttps://www.offensity.com/en/blog/user-impersonation-via-stolen-uuid-code-in-keycloak-cve-2023-0264/
RELATED WRITEUPS
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDC
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
Escalating From Reader To Contributor In Azure API Management
Privilege Escalation
Microsoft Windows MSI Installer - Repair to SYSTEM - A detailed journey
Privilege EscalationLocal Privilege Escalation
Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation
Privilege Escalation

Built with ❤️ by Shubham Rawat