Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-0264 PoC — keycloak 授权问题漏洞

Source
Associated Vulnerability
Title: keycloak 授权问题漏洞 (CVE-2023-0264)
Description:A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
Description
A small PoC for the Keycloak vulnerability CVE-2023-0264
Readme
# PoC for CVE-2023-0264

_Keycloak vulnerability that allows session hijacking during authorization code flow_

See https://github.com/advisories/GHSA-9g98-5mj6-f9mv

## Prerequisites

- Docker
- curl
- jq
- python3 or another tool to serve static files on HTTP

## Steps to reproduce

1. Start Keycloak container with `./run-keycloak-container.sh`
2. Create two users `alice` and `mallory` with `./create-users.sh`
3. Serve the static files from this repo, e.g., `python3 -m http.server 8000`
4. Open http://localhost:8000/index.html in **two** browser sessions
5. Start logging in with `alice` and password `test` in session 1 and copy the session id from the prompt
6. Start logging in with `mallory` and password `test` in session 2 and paste the session id from `alice` into the
   prompt (and press _OK_)
7. You should be logged in as `alice` in session 2 from `mallory`
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →