CVE Database
/

CVE-2024-12369

Back to search

CVE-2024-12369

Published: Dec 9, 2024

Modified: Apr 30, 2026

PUBLISHED

CVSS v3.1

4.2

MEDIUM

Description

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.

VendorProductVersions

Unknown

wildfly

affected
0 - <= 34.0.1.Final

Red Hat

Red Hat JBoss Enterprise Application Platform 8

All versions

Red Hat

Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8

unaffected
0:2.2.9-1.Final_redhat_00001.1.el8eap - < *

Red Hat

Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9

unaffected
0:2.2.9-1.Final_redhat_00001.1.el9eap - < *

Red Hat

Red Hat Build of Keycloak

All versions

Red Hat

Red Hat JBoss Enterprise Application Platform 7

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2024-12369 | MEDIUM (4.2) - Security Vulnerability | QwikSec