CVE-2023-0264 is an authentication flaw in Keycloak OpenID Connect user-authentication handling. Insufficiently protected request-derived information, described as a UUID code, can be reused within the same realm. Keycloak may incorrectly authenticate the resulting request, allowing an authenticated attacker to impersonate the affected user and obtain newly generated session tokens. Keycloak 18.0.6 includes a fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, containerized proof-of-concept front-end for CVE-2023-0264 targeting Keycloak OIDC session hijacking behavior. It is not a general exploit framework; instead, it packages a static HTML/JavaScript application behind nginx and injects runtime configuration through a shell script executed at container startup. Repository structure: README.md explains deployment and Keycloak prerequisites; Dockerfile builds an nginx:alpine image and installs the static app plus startup script; docker-compose.yml exposes the app on host port 5174 and defines KEYCLOAK_URL/REALM/CLIENT_ID; docker-entrypoint.d/40-poc-config.sh generates /usr/share/nginx/html/config.js from environment variables; index1.html contains the actual PoC logic and UI. Main exploit capability: the browser app performs an OIDC authorization code flow against a configured Keycloak instance, exposes a pre-initialization hook that reveals the current session_id and allows substitution with another session identifier, then exchanges the returned authorization code for tokens. This demonstrates session hijacking/session confusion behavior rather than remote code execution. The result is token acquisition associated with an injected session context. Operational flow: when loaded, the app reads runtime config, computes Keycloak endpoints, redirects the browser to the authorization endpoint, receives the authorization code on return, invokes the session hook, posts the code to the token endpoint, parses the returned ID token, and updates the UI to show authenticated state. The PoC depends on permissive/expected Keycloak client configuration for redirect URIs and web origins, and on browser trust of the Keycloak TLS certificate if self-signed. Notable observables include the documented front-end URL http://maquina:5174, the sample Keycloak target https://147.93.70.139:8443, generated config file paths under /usr/share/nginx/html, and the OIDC authorization/token/logout endpoints derived from the configured Keycloak base URL, realm, and client ID.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2023-0264, a session hijacking vulnerability in Keycloak's OAuth2 authorization code flow. The repository contains scripts to set up a vulnerable Keycloak instance in Docker (run-keycloak-container.sh), create two test users (create-users.sh), and static web files (index.html, client2.html) that interact with the Keycloak server using a custom JavaScript flow. The exploit works by intercepting and modifying the session ID embedded in the OAuth2 authorization code, allowing an attacker to hijack another user's session. The README provides step-by-step instructions to reproduce the vulnerability locally. The main attack vector is via a browser, targeting a Keycloak server running on localhost. The repository is structured for easy local testing and demonstration of the vulnerability, and does not contain weaponized or automated exploitation code beyond the PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keycloak user-impersonation vulnerability through a stolen UUID code.
Keycloak user-impersonation vulnerability involving a stolen UUID code.
Keycloak user-impersonation vulnerability through a stolen UUID code.
Keycloak user-impersonation vulnerability through a stolen UUID code.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.