Client Spoofing within the Keycloak Device Authorisation Grant
Description
Published to the GitHub Advisory Database
Jun 30, 2023
Reviewed
Jun 30, 2023
Published by the National Vulnerability Database
Dec 21, 2023
Last updated
Dec 21, 2023
Under certain pre-conditions the vulnerability allows an attacker to spoof parts of the device flow and use a device_code to retrieve an access token for other OAuth clients.
References