Bug 2258456 (CVE-2024-0560) - CVE-2024-0560 apicast: use_3scale_oidc_issuer_endpoint of Token Introspection policy isn't compatible with RH-SSO 7.5 or later versions
Summary: CVE-2024-0560 apicast: use_3scale_oidc_issuer_endpoint of Token Introspection...
Keywords:
Status: NEW
Alias: CVE-2024-0560
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2258454
TreeView+ depends on / blocked
 
Reported: 2024-01-15 13:16 UTC by Patrick Del Bello
Modified: 2024-02-28 16:06 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: ---
Doc Text:
A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endpoint from the token_introspection_endpoint field, but the field was removed on RH-SSO 7.5. As a result, the policy doesn't inspect tokens, it determines that all tokens are valid.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Patrick Del Bello 2024-01-15 13:16:32 UTC
A vulnerability was found in 3Scale when using with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, Token Introspection policy discovers the Token Introspection endpoint from the token_introspection_endpoint field, but the field was removed on RH-SSO 7.5. As the result, the policy doesn't inspect tokens; it determines that all tokens are valid. 

Using an alternate auth_type: auth_type: client_id+client_secret. Disabling the policy entirely might be a temporary solution if the alternate {{auth_type is not feasible for some reason. The only purpose the token introspection endpoint serves is for sessions which are revoked in RH SSO *before the standard TTL expires via the exp claim.


Note You need to log in before you can comment on or make changes to this bug.