Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-3597

15
FAUCET Score

CVE-2023-3597 is a medium-severity flaw in Keycloak's client step-up authentication, specifically within org.keycloak.authentication. An authenticated remote user can exploit this vulnerability to register a false second authentication factor alongside an existing one, thereby bypassing the intended multi-factor authentication. The attack requires low privileges and high attack complexity, with potential for low impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Build Of Keycloak 22
Range not provided by sourceCNA affecteddefault affected
Https://Www.Keycloak.Org/Keycloak
>= 0, < 22.0.10, >= 23.0.0, < 24.0.3CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.60%
Probability of exploitation in next 30 days
EPSS Percentile
45.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0060 is in the 35th percentile among its peer group of 1,428 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

mavenpatch availablevia ghsa
Product: org.keycloak:keycloak-servicesFixed in: 22.0.10
mavenpatch availablevia ghsa
Product: org.keycloak:keycloak-servicesFixed in: 24.0.3
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 22Fixed in: rhbk/keycloak-operator-bundle:22.0.10-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 22Fixed in: rhbk/keycloak-rhel9:22-13
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 22Fixed in: rhbk/keycloak-rhel9-operator:22-16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 22.0.10Fixed in: keycloak
View patch
redhatpatch availablevia redhat_api
Product: RHSSO 7.6.8
View patch

Vendor Advisories (2)

mavenGHSA-4f53-xh3v-g8x4medium

Keycloak secondary factor bypass in step-up authentication

Apr 17, 2024
redhatCVE-2023-3597Moderate

keycloak: secondary factor bypass in step-up authentication

Apr 15, 2024

References

access.redhat.com / errata/RHSA-2024:1866
access.redhat.com / errata/RHSA-2024:1867
access.redhat.com / errata/RHSA-2024:1868
access.redhat.com / security/cve/CVE-2023-3597
bugzilla.redhat.com / show_bug.cgi